{"api_version":"1","generated_at":"2026-07-23T11:14:45+00:00","cve":"CVE-2018-21268","urls":{"html":"https://cve.report/CVE-2018-21268","api":"https://cve.report/api/cve/CVE-2018-21268.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-21268","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-21268"},"summary":{"title":"CVE-2018-21268","description":"The traceroute (aka node-traceroute) package through 1.0.0 for Node.js allows remote command injection via the host parameter. This occurs because the Child.exec() method, which is considered to be not entirely safe, is used. In particular, an OS command can be placed after a newline character.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2020-06-25 17:15:00","updated_at":"2023-11-07 02:56:00"},"problem_types":["CWE-74"],"metrics":[],"references":[{"url":"https://www.npmjs.com/advisories/1465","name":"https://www.npmjs.com/advisories/1465","refsource":"MISC","tags":["Third Party Advisory"],"title":"Overview","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://medium.com/%40shay_62828/shell-command-injection-through-traceroute-npm-package-a4cf7b6553e3","name":"https://medium.com/%40shay_62828/shell-command-injection-through-traceroute-npm-package-a4cf7b6553e3","refsource":"","tags":[],"title":"Shell Command Injection Through Traceroute NPM Package | by OP Innovate | Medium","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.op-c.net/2020/06/17/shell-command-injection-through-traceroute-npm-package/","name":"https://www.op-c.net/2020/06/17/shell-command-injection-through-traceroute-npm-package/","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"Page not found – OP Innovate","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"https://www.linkedin.com/posts/op-innovate_shell-command-injection-through-traceroute-activity-6678956453086191616-Rcpy","name":"https://www.linkedin.com/posts/op-innovate_shell-command-injection-through-traceroute-activity-6678956453086191616-Rcpy","refsource":"MISC","tags":["Third Party Advisory"],"title":"OP Innovate on LinkedIn: Shell Command Injection Through Traceroute NPM Package","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://medium.com/@shay_62828/shell-command-injection-through-traceroute-npm-package-a4cf7b6553e3","name":"https://medium.com/@shay_62828/shell-command-injection-through-traceroute-npm-package-a4cf7b6553e3","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"Shell Command Injection Through Traceroute NPM Package | by OP Innovate | Medium","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://snyk.io/vuln/npm:traceroute:20160311","name":"https://snyk.io/vuln/npm:traceroute:20160311","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"Shell Command Injection in traceroute | Snyk","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.npmjs.com/package/traceroute","name":"https://www.npmjs.com/package/traceroute","refsource":"MISC","tags":["Product","Third Party Advisory"],"title":"traceroute  -  npm","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/jaw187/node-traceroute/commit/b99ee024a01a40d3d20a92ad3769cc78a3f6386f","name":"https://github.com/jaw187/node-traceroute/commit/b99ee024a01a40d3d20a92ad3769cc78a3f6386f","refsource":"MISC","tags":["Patch","Third Party Advisory"],"title":"conversion to spawn and stream · jaw187/node-traceroute@b99ee02 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://github.com/jaw187/node-traceroute/tags","name":"https://github.com/jaw187/node-traceroute/tags","refsource":"MISC","tags":["Third Party Advisory"],"title":"Tags · jaw187/node-traceroute · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-21268","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-21268","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"21268","vulnerable":"1","versionEndIncluding":"1.0.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"traceroute_project","cpe5":"traceroute","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"node.js","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2018-21268","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The traceroute (aka node-traceroute) package through 1.0.0 for Node.js allows remote command injection via the host parameter. This occurs because the Child.exec() method, which is considered to be not entirely safe, is used. In particular, an OS command can be placed after a newline character."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://www.linkedin.com/posts/op-innovate_shell-command-injection-through-traceroute-activity-6678956453086191616-Rcpy","refsource":"MISC","name":"https://www.linkedin.com/posts/op-innovate_shell-command-injection-through-traceroute-activity-6678956453086191616-Rcpy"},{"url":"https://www.op-c.net/2020/06/17/shell-command-injection-through-traceroute-npm-package/","refsource":"MISC","name":"https://www.op-c.net/2020/06/17/shell-command-injection-through-traceroute-npm-package/"},{"url":"https://medium.com/@shay_62828/shell-command-injection-through-traceroute-npm-package-a4cf7b6553e3","refsource":"MISC","name":"https://medium.com/@shay_62828/shell-command-injection-through-traceroute-npm-package-a4cf7b6553e3"},{"url":"https://github.com/jaw187/node-traceroute/tags","refsource":"MISC","name":"https://github.com/jaw187/node-traceroute/tags"},{"url":"https://www.npmjs.com/package/traceroute","refsource":"MISC","name":"https://www.npmjs.com/package/traceroute"},{"url":"https://www.npmjs.com/advisories/1465","refsource":"MISC","name":"https://www.npmjs.com/advisories/1465"},{"url":"https://snyk.io/vuln/npm:traceroute:20160311","refsource":"MISC","name":"https://snyk.io/vuln/npm:traceroute:20160311"},{"url":"https://github.com/jaw187/node-traceroute/commit/b99ee024a01a40d3d20a92ad3769cc78a3f6386f","refsource":"MISC","name":"https://github.com/jaw187/node-traceroute/commit/b99ee024a01a40d3d20a92ad3769cc78a3f6386f"}]},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AC:L/AV:N/A:L/C:H/I:H/PR:N/S:C/UI:N","version":"3.0"}}},"nvd":{"publishedDate":"2020-06-25 17:15:00","lastModifiedDate":"2023-11-07 02:56:00","problem_types":["CWE-74"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:traceroute_project:traceroute:*:*:*:*:*:node.js:*:*","versionEndIncluding":"1.0.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"21268","Ordinal":"176680","Title":"CVE-2018-21268","CVE":"CVE-2018-21268","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"21268","Ordinal":"1","NoteData":"The traceroute (aka node-traceroute) package through 1.0.0 for Node.js allows remote command injection via the host parameter. This occurs because the Child.exec() method, which is considered to be not entirely safe, is used. In particular, an OS command can be placed after a newline character.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"21268","Ordinal":"2","NoteData":"2020-06-25","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"21268","Ordinal":"3","NoteData":"2020-06-25","Type":"Other","Title":"Modified"}]}}}