@cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized `--workspace` Argument
21Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 8.5epss 0.2%
probabilidade de exploração
0.2%top 85% das CVEs
exploração observada
nãonenhuma fonte reporta
@cyclonedx/cyclonedx-npm creates CycloneDX Software Bill of Materials from npm projects. From 2.1.0 before 5.0.0, the CLI passes user-supplied --workspace values to a subshell without proper sanitization when npm_execpath is unset or empty, allowing arbitrary OS command execution with the privileges of the invoking user. This issue is fixed in version 5.0.0.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Produtos afetados
CycloneDX · cyclonedx-node-npmReferências
https://github.com/CycloneDX/cyclonedx-node-npm/commit/9f646253f4263d8644dadb86e5597fad996f688fhttps://github.com/CycloneDX/cyclonedx-node-npm/pull/1476https://github.com/CycloneDX/cyclonedx-node-npm/releases/tag/v5.0.0https://github.com/CycloneDX/cyclonedx-node-npm/security/advisories/GHSA-v75r-vx73-82pj