VDB
Sign up
CRITICAL9.8

GHSA-whq6-mj2r-mjqc

OS Command Injection in lsof

Details

All versions including 0.0.4 of lsof npm module are vulnerable to Command Injection. Every exported method used by the package uses the exec function to parse user input.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/lsof
Introduced in: 0

No fixed version published yet for lsof (npm). Pin to a known-safe version or switch to an alternative.

References