CRITICAL9.8
GHSA-vmqq-7qvx-68qx
promise-probe OS command injection vulnerability
Quick fix
GHSA-vmqq-7qvx-68qx — promise-probe: upgrade to the fixed version with the command below.
npm install promise-probe@0.1.10Details
promise-probe before 0.10.0 allows remote attackers to perform a command injection attack. The `file`, `outputFile` and `options` functions can be controlled by users without any sanitization.
Are you affected?
Enter the version of the package you're using.