CRITICAL9.8
GHSA-ph32-23p8-9rw5
Improper Input Validation in network-manager
Details
network-manager through 1.0.2 allows remote attackers to execute arbitrary commands via the "execSync()" argument.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/network-manager
Introduced in:
0No fixed version published yet for network-manager (npm). Pin to a known-safe version or switch to an alternative.