VDB
Sign up
CRITICAL9.8

GHSA-cqr2-xhg6-p268

OS Command Injection in node-mpv

Details

node-mpv through 1.4.3 is vulnerable to Command Injection. It allows execution of arbitrary commands via the options argument.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/node-mpv
Introduced in: 0

No fixed version published yet for node-mpv (npm). Pin to a known-safe version or switch to an alternative.

References