Lucene search

K
osvGoogleOSV:GHSA-WQ7Q-5V6J-XFV6
HistoryMay 07, 2021 - 4:06 p.m.

Command Injection in picotts

2021-05-0716:06:11
Google
osv.dev
8
picotts
command injection
arbitrary commands

EPSS

0.005

Percentile

76.1%

This affects all versions up to and including version 0.1.1 of package picotts. If attacker-controlled user input is given to the say function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.

EPSS

0.005

Percentile

76.1%

Related for OSV:GHSA-WQ7Q-5V6J-XFV6