VDB
Sign up
HIGH7.3

GHSA-m8fm-mv5w-33pv

Command Injection in psnode

Details

This affects all current versions of package psnode. If attacker-controlled user input is given to the kill function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/psnode
Introduced in: 0

No fixed version published yet for psnode (npm). Pin to a known-safe version or switch to an alternative.

References