VDB
Sign up
CRITICAL9.8

GHSA-hmw2-mvvh-jf5j

OS Command Injection in enpeem

Details

enpeem through 2.2.0 allows execution of arbitrary commands. The "options.dir" argument is provided to the "exec" function without any sanitization.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/enpeem
Introduced in: 0

No fixed version published yet for enpeem (npm). Pin to a known-safe version or switch to an alternative.

References