← back
CVE-2019-5413CWE-94

CVE-2019-5413

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 3.4%
exploitation probability
3.4%top 12% of all CVEs
observed exploitation
nono source reports it
An attacker can use the format parameter to inject arbitrary commands in the npm package morgan < 1.9.1.
Affected products
n/a · morgan