CRITICAL9.8
GHSA-r9vm-rhmf-7hxx
OS Command Injection in im-resize
Details
im-resize through 2.3.2 allows remote attackers to execute arbitrary commands via the "exec" argument. The cmd argument used within index.js, can be controlled by user without any sanitization.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/im-resize
Introduced in:
0No fixed version published yet for im-resize (npm). Pin to a known-safe version or switch to an alternative.