GHSA-5fw9-fq32-wv5p

Suggest an improvement
Source
https://github.com/advisories/GHSA-5fw9-fq32-wv5p
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/12/GHSA-5fw9-fq32-wv5p/GHSA-5fw9-fq32-wv5p.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-5fw9-fq32-wv5p
Aliases
  • CVE-2020-7789
  • SNYK-JAVA-ORGWEBJARSNPM-1050371
  • SNYK-JS-NODENOTIFIER-1035794
Published
2020-12-21T16:04:07Z
Modified
2024-09-03T06:27:18.541773Z
Severity
  • 5.6 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
Summary
OS Command Injection in node-notifier
Details

This affects the package node-notifier before 8.0.1. It allows an attacker to run arbitrary commands on Linux machines due to the options params not being sanitised when being passed an array.

References

Affected packages

npm / node-notifier

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
8.0.1