VDB
Sign up
MEDIUM6.5

GHSA-2gmp-34j9-fqjm

Replicator deserializes untrusted user input

Details

An unauthenticated Remote Code Execution (RCE) vulnerability exists in applications that use the Replicator node package manager (npm) version 1.0.5 to deserialize untrusted user input and execute the resulting object.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/replicator
Introduced in: 0

No fixed version published yet for replicator (npm). Pin to a known-safe version or switch to an alternative.

References