VDB
Sign up
CRITICAL

GHSA-hfq9-rfpv-j8r8

Command Injection in pidusage

Quick fix

GHSA-hfq9-rfpv-j8r8 — pidusage: upgrade to the fixed version with the command below.

npm install pidusage@1.1.5

Details

Affected versions of `pidusage` pass unsanitized input to `child_process.exec()`, resulting in arbitrary code execution in the `ps` method. This package is vulnerable to this PoC on Darwin, SunOS, FreeBSD, and AIX.

Windows and Linux are not vulnerable.

## Proof of Concept ``` var pid = require('pidusage'); pid.stat('1 && /usr/local/bin/python'); ```

## Recommendation

Update to version 1.1.5 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/pidusage
Introduced in: 0Fixed in: 1.1.5
Fixnpm install pidusage@1.1.5

References