Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:30024
HistoryApr 19, 2021 - 5:08 a.m.

Arbitrary Code Execution

2021-04-1905:08:31
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5
picotts
arbitrary code execution
vulnerability
user-provided input
child_process.exec
sanitization

EPSS

0.005

Percentile

76.1%

picotts is vulnerable to arbitrary code execution. The vulnerability exists due to the lack of sanitization of user-provided input to the say function which is subsequently parsed in the child_process.exec function.

EPSS

0.005

Percentile

76.1%