CRITICAL9.8
GHSA-cqr2-xhg6-p268
OS Command Injection in node-mpv
Details
node-mpv through 1.4.3 is vulnerable to Command Injection. It allows execution of arbitrary commands via the options argument.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/node-mpv
Introduced in:
0No fixed version published yet for node-mpv (npm). Pin to a known-safe version or switch to an alternative.