CRITICAL9.8
GHSA-3q9x-w53p-jg53
OS Command Injection in heroku-addonpool
Quick fix
GHSA-3q9x-w53p-jg53 — heroku-addonpool: upgrade to the fixed version with the command below.
npm install heroku-addonpool@0.1.16Details
heroku-addonpool through 0.1.15 is vulnerable to Command Injection. The second parameter of the exported function `HerokuAddonPool(id, app, opt)` can be controlled by users without any sanitization.
**PoC** ```js var Root = require("heroku-addonpool"); var root = Root("sss", "& touch JHU", {}); root.setup(); ```
Are you affected?
Enter the version of the package you're using.