VDB
Sign up
CRITICAL9.8

GHSA-r9vm-rhmf-7hxx

OS Command Injection in im-resize

Details

im-resize through 2.3.2 allows remote attackers to execute arbitrary commands via the "exec" argument. The cmd argument used within index.js, can be controlled by user without any sanitization.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/im-resize
Introduced in: 0

No fixed version published yet for im-resize (npm). Pin to a known-safe version or switch to an alternative.

References