VDB
Sign up
CRITICAL9.8

GHSA-3q9x-w53p-jg53

OS Command Injection in heroku-addonpool

Quick fix

GHSA-3q9x-w53p-jg53 — heroku-addonpool: upgrade to the fixed version with the command below.

npm install heroku-addonpool@0.1.16

Details

heroku-addonpool through 0.1.15 is vulnerable to Command Injection. The second parameter of the exported function `HerokuAddonPool(id, app, opt)` can be controlled by users without any sanitization.

**PoC** ```js var Root = require("heroku-addonpool"); var root = Root("sss", "& touch JHU", {}); root.setup(); ```

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/heroku-addonpool
Introduced in: 0Fixed in: 0.1.16
Fixnpm install heroku-addonpool@0.1.16

References