VDB
Sign up
CRITICAL9.8

GHSA-h2p3-h48h-9jj7

PIDUsage Enables OS Command Injection

Quick fix

GHSA-h2p3-h48h-9jj7 — pidusage: upgrade to the fixed version with the command below.

npm install pidusage@1.1.5

Details

### Overview Affected versions of pidusage pass unsanitized input to `child_process.exec()`, resulting in arbitrary code execution in the `ps` method.

This package is vulnerable to this PoC on Darwin, SunOS, FreeBSD, and AIX.

Windows and Linux are not vulnerable.

### Proof of Concept ```js var pid = require('pidusage'); pid.stat('1 && /usr/local/bin/python'); ```

### Remediation Update to version 1.1.5 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/pidusage
Introduced in: 0Fixed in: 1.1.5
Fixnpm install pidusage@1.1.5

References