VDB
Sign up
CRITICAL9.8

GHSA-426h-24vj-qwxf

Command Injection in npm-programmatic

Details

All versions of `npm-programmatic ` are vulnerable to Command Injection. The package fails to sanitize input rules and passes it directly to an `exec` call on the `install`, `uninstall` and `list` functions . This may allow attackers to execute arbitrary code in the system if the package name passed to the function is user-controlled.

## Recommendation

No fix is currently available. Consider using an alternative package until a fix is made available.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/npm-programmatic
Introduced in: 0

No fixed version published yet for npm-programmatic (npm). Pin to a known-safe version or switch to an alternative.

References