GHSA-8j6j-4h2c-c65p
UNKNOWNVersions of require-node prior to 1.3.4 for 1.x and 2.0.4 for 2.x are vulnerable to Arbitrary Code Execution. The package fails to sanitize requests to the require-node endpoint, allowing attackers to execute arbitrary code in the server through the injection of OS commands in the request body.
- Affected
- >=0, <1.3.4, >=2.0.0, <2.0.4
- Fixed in
- not stated
- Weakness
- CWE-78
- Published
- 2020-09-03
- Source
- osv