QID 982918
QID 982918: Nodejs (npm) Security Update for madge (GHSA-753c-phhg-cj29)
This affects the package madge before 4.0.1. It is possible to specify a custom Graphviz path via the graphVizPath option parameter which when the .image(), .svg() or .dot() functions are called, is executed by the childprocess.exec function.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-753c-phhg-cj29 for updates pertaining to this vulnerability.
Vendor References
- GHSA-753c-phhg-cj29 -
github.com/advisories/GHSA-753c-phhg-cj29
CVEs related to QID 982918
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-753c-phhg-cj29 | madge |
|