GHSA-95rp-6gqp-6622

    Dashboard / Vulnerabilities / GHSA-95rp-6gqp-6622

    GHSA-95rp-6gqp-6622

    Published: 30 Aug 2023Last Modified: 8 Nov 2023

    Summary: Command Injection Vulnerability in find-exec

    Details: Older versions of the package are vulnerable to Command Injection as an attacker controlled parameter. As a result, attackers may run malicious commands. For example: ``` const find = require("find-exec"); find("mplayer; touch hacked") ``` This creates a file named "hacked" on the filesystem. You should never allow users to control commands to find, since this package attempts to run every command provided. Thanks to @miguelafmonteiro for reporting.

    Affected packages

    Package

    Name: find-exec

    Purl: pkg:npm/find-exec

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -1.0.3

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-95rp-6gqp-6622 | CVE-DB