VDB
Sign up
CRITICAL9.8

GHSA-mvhf-547c-h55r

thumbler allows OS Command Injection

Details

thumbler through 1.1.2 allows OS command injection via the input, output, time, or size parameter in the thumbnail() function because user input is concatenated into a shell command string passed to child_process.exec() without proper sanitization or escaping.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/thumbler
Introduced in: 0

No fixed version published yet for thumbler (npm). Pin to a known-safe version or switch to an alternative.

References