VDB
Sign up
CRITICAL9.8

GHSA-qfxv-qqvg-24pg

OS Command Injection in im-metadata

Details

im-metadata through 3.0.1 allows remote attackers to execute arbitrary commands via the "exec" argument. It is possible to inject arbitrary commands as part of the metadata options which is given to the "exec" function.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/im-metadata
Introduced in: 0

No fixed version published yet for im-metadata (npm). Pin to a known-safe version or switch to an alternative.

References