CRITICAL
GHSA-hfq9-rfpv-j8r8
Command Injection in pidusage
Quick fix
GHSA-hfq9-rfpv-j8r8 — pidusage: upgrade to the fixed version with the command below.
npm install pidusage@1.1.5Details
Affected versions of `pidusage` pass unsanitized input to `child_process.exec()`, resulting in arbitrary code execution in the `ps` method. This package is vulnerable to this PoC on Darwin, SunOS, FreeBSD, and AIX.
Windows and Linux are not vulnerable.
## Proof of Concept ``` var pid = require('pidusage'); pid.stat('1 && /usr/local/bin/python'); ```
## Recommendation
Update to version 1.1.5 or later.
Are you affected?
Enter the version of the package you're using.