CRITICAL9.8
GHSA-h2p3-h48h-9jj7
PIDUsage Enables OS Command Injection
Quick fix
GHSA-h2p3-h48h-9jj7 — pidusage: upgrade to the fixed version with the command below.
npm install pidusage@1.1.5Details
### Overview Affected versions of pidusage pass unsanitized input to `child_process.exec()`, resulting in arbitrary code execution in the `ps` method.
This package is vulnerable to this PoC on Darwin, SunOS, FreeBSD, and AIX.
Windows and Linux are not vulnerable.
### Proof of Concept ```js var pid = require('pidusage'); pid.stat('1 && /usr/local/bin/python'); ```
### Remediation Update to version 1.1.5 or later.
Are you affected?
Enter the version of the package you're using.