VDB
Sign up
CRITICAL9.8

GHSA-ph32-23p8-9rw5

Improper Input Validation in network-manager

Details

network-manager through 1.0.2 allows remote attackers to execute arbitrary commands via the "execSync()" argument.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/network-manager
Introduced in: 0

No fixed version published yet for network-manager (npm). Pin to a known-safe version or switch to an alternative.

References