@cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized `--workspace` Argument
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 8.5epss 0.2%
probabilidad de explotación
0.2%top 87% de las CVE
explotación observada
noninguna fuente lo reporta
@cyclonedx/cyclonedx-npm creates CycloneDX Software Bill of Materials from npm projects. From 2.1.0 before 5.0.0, the CLI passes user-supplied --workspace values to a subshell without proper sanitization when npm_execpath is unset or empty, allowing arbitrary OS command execution with the privileges of the invoking user. This issue is fixed in version 5.0.0.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
CycloneDX · cyclonedx-node-npmReferencias
https://github.com/CycloneDX/cyclonedx-node-npm/commit/9f646253f4263d8644dadb86e5597fad996f688fhttps://github.com/CycloneDX/cyclonedx-node-npm/pull/1476https://github.com/CycloneDX/cyclonedx-node-npm/releases/tag/v5.0.0https://github.com/CycloneDX/cyclonedx-node-npm/security/advisories/GHSA-v75r-vx73-82pj