QID 982776
QID 982776: Nodejs (npm) Security Update for enpeem (GHSA-hmw2-mvvh-jf5j)
enpeem through 2.2.0 allows execution of arbitrary commands. The "options.dir" argument is provided to the "exec" function without any sanitization.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-hmw2-mvvh-jf5j for updates pertaining to this vulnerability.
Vendor References
- GHSA-hmw2-mvvh-jf5j -
github.com/advisories/GHSA-hmw2-mvvh-jf5j
CVEs related to QID 982776
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-hmw2-mvvh-jf5j | enpeem |
|