OS Command Injection in lsof
High severity
GitHub Reviewed
Published
Apr 13, 2021
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Jan 29, 2020
Reviewed
Mar 29, 2021
Published to the GitHub Advisory Database
Apr 13, 2021
Last updated
Feb 1, 2023
All versions including 0.0.4 of lsof npm module are vulnerable to Command Injection. Every exported method used by the package uses the exec function to parse user input.
References