PIDUsage Enables OS Command Injection
Critical severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Oct 16, 2024
Description
Published by the National Vulnerability Database
Nov 17, 2017
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Apr 22, 2024
Last updated
Oct 16, 2024
Overview
Affected versions of pidusage pass unsanitized input to
child_process.exec()
, resulting in arbitrary code execution in theps
method.This package is vulnerable to this PoC on Darwin, SunOS, FreeBSD, and AIX.
Windows and Linux are not vulnerable.
Proof of Concept
Remediation
Update to version 1.1.5 or later.
References