CRITICAL9.8
GHSA-mc7w-4cjf-c973
OS Command Injection in node-opencv
Quick fix
GHSA-mc7w-4cjf-c973 — opencv: upgrade to the fixed version with the command below.
npm install opencv@6.1.0Details
utils/find-opencv.js in node-opencv (aka OpenCV bindings for Node.js) prior to 6.1.0 is vulnerable to Command Injection. It does not validate user input allowing attackers to execute arbitrary commands.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2019-10061[ADVISORY]
- https://github.com/peterbraden/node-opencv/commit/81a4b8620188e89f7e4fc985f3c89b58d4bcc86b[WEB]
- https://github.com/peterbraden/node-opencv/commit/aaece6921d7368577511f06c94c99dd4e9653563[WEB]
- https://github.com/peterbraden/node-opencv[WEB]
- https://www.npmjs.com/advisories/789[WEB]
- https://www.npmjs.com/package/opencv[WEB]