VDB
Sign up
CRITICAL

GHSA-q5pq-pgrv-fh89

dns-sync command injection vulnerability

Quick fix

GHSA-q5pq-pgrv-fh89 — dns-sync: upgrade to the fixed version with the command below.

npm install dns-sync@0.1.1

Details

The dns-sync module before 0.1.1 for node.js allows context-dependent attackers to execute arbitrary commands via shell metacharacters in the first argument to the resolve API function.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/dns-sync
Introduced in: 0Fixed in: 0.1.1
Fixnpm install dns-sync@0.1.1

References