QID 994765

Date Published: 2023-08-10

QID 994765: NodeJs (Npm) Security Update for import-in-the-middle (GHSA-5r27-rw8r-7967)

The import-in-the-middle loader works by generating a wrapper module on the fly. The wrapper uses the module specifier to load the original module and add some wrapping code. It allows for remote code execution in cases where an application passes user-supplied input directly to an import() function.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Refer to Github security advisory GHSA-5r27-rw8r-7967 for updates and patch information.
    Vendor References

    CVEs related to QID 994765

    Software Advisories
    Advisory ID Software Component Link
    GHSA-5r27-rw8r-7967 import-in-the-middle URL Logo github.com/advisories/GHSA-5r27-rw8r-7967