VDB
Sign up
CRITICAL9.8

GHSA-vmqq-7qvx-68qx

promise-probe OS command injection vulnerability

Quick fix

GHSA-vmqq-7qvx-68qx — promise-probe: upgrade to the fixed version with the command below.

npm install promise-probe@0.1.10

Details

promise-probe before 0.10.0 allows remote attackers to perform a command injection attack. The `file`, `outputFile` and `options` functions can be controlled by users without any sanitization.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/promise-probe
Introduced in: 0Fixed in: 0.1.10
Fixnpm install promise-probe@0.1.10

References