VDB
Sign up
MEDIUM6.4

GHSA-vm67-7vmg-66vm

Arbitrary Command Injection in portprocesses

Quick fix

GHSA-vm67-7vmg-66vm — portprocesses: upgrade to the fixed version with the command below.

npm install portprocesses@1.0.5

Details

### Impact

An Arbitrary Command Injection vulnerability was reported in `portprocesses` impacting versions <= 1.0.4.

### Example (Proof of Concept)

The following example demonstrates the vulnerability and will run `touch success` therefore creating a file named `success`.

```js const portprocesses = require("portprocesses");

portprocesses.killProcess("$(touch success)"); ```

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/portprocesses
Introduced in: 0Fixed in: 1.0.5
Fixnpm install portprocesses@1.0.5

References