Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:28590
HistoryDec 14, 2020 - 6:36 a.m.

Command Injection

2020-12-1406:36:16
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

0.002 Low

EPSS

Percentile

57.6%

node-notifier is vulnerable to remote code execution (RCE). An attacker can send malicious commands via options params as it is not sanitized when being passed as an array.

CPENameOperatorVersion
node-notifierle8.0.0
node-notifierle5.4.5

0.002 Low

EPSS

Percentile

57.6%