CRITICAL9.8
GHSA-vf26-7gjf-f92r
OS Command Injection in rpi
Details
rpi through 0.0.3 allows execution of arbritary commands. The variable pinNumbver in function GPIO within src/lib/gpio.js is used as part of the arguement of exec function without any sanitization.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/rpi
Introduced in:
0No fixed version published yet for rpi (npm). Pin to a known-safe version or switch to an alternative.