GHSA-wp7m-mrvf-599c
CRITICALCVE-2019-15597All versions of node-df are vulnerable to Command Injection. The package fails to sanitize filenames passed to the file option. If this value is user-controlled it may allow attackers to run arbitrary commands in the server.
- Affected
- <= 0.1.4
- Fixed in
- not stated
- Weakness
- CWE-94
- Published
- 2020-02-14
- Source
- github