VDB
Sign up
CRITICAL9.8

GHSA-8j9v-qhp4-wv55

Node-Traceroute RCE Vulnerability

Details

The traceroute (aka node-traceroute) package through 1.0.0 for Node.js allows remote command injection via the host parameter. This occurs because the `Child.exec()` method, which is considered to be not entirely safe, is used. In particular, an OS command can be placed after a newline character.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/traceroute
Introduced in: 0

No fixed version published yet for traceroute (npm). Pin to a known-safe version or switch to an alternative.

References