GHSA-8j6j-4h2c-c65p
CRITICALVersions of require-node prior to 1.3.4 for 1.x and 2.0.4 for 2.x are vulnerable to Arbitrary Code Execution. The package fails to sanitize requests to the require-node endpoint, allowing attackers to execute arbitrary code in the server through the injection of OS commands in the request body.
- Affected
- >= 2.0.0, < 2.0.4, < 1.3.4
- Fixed in
- 2.0.4
- Weakness
- CWE-78
- Published
- 2020-09-03
- Source
- github