QID 981912
QID 981912: Nodejs (npm) Security Update for node-prompt-here (GHSA-f8fh-8rgm-227h)
node-prompt-here through 1.0.1 allows execution of arbitrary commands. The "runCommand()" is called by "getDevices()" function in file "linux/manager.js", which is required by the "index. process.env.NM_CLI" in the file "linux/manager.js". This function is used to construct the argument of function "execSync()", which can be controlled by users without any sanitization.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-f8fh-8rgm-227h for updates pertaining to this vulnerability.
Vendor References
- GHSA-f8fh-8rgm-227h -
github.com/advisories/GHSA-f8fh-8rgm-227h
CVEs related to QID 981912
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-f8fh-8rgm-227h | node-prompt-here |
|