CRITICAL9.8
GHSA-mvhf-547c-h55r
thumbler allows OS Command Injection
Details
thumbler through 1.1.2 allows OS command injection via the input, output, time, or size parameter in the thumbnail() function because user input is concatenated into a shell command string passed to child_process.exec() without proper sanitization or escaping.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/thumbler
Introduced in:
0No fixed version published yet for thumbler (npm). Pin to a known-safe version or switch to an alternative.