PT-2026-63527 · Npm · Publint
CVSS v3.1
5.3
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
publint versions prior to 0.1.5
Description
An OS command injection issue exists within the package-manager Command Handler component. The flaw is located in the
child process.exec() function within the src/node/pack.js file. This allows for the execution of arbitrary operating system commands, provided the attacker has local access. OS command injection is a flaw where an application passes unsafe user-supplied data to a system shell, allowing the execution of unauthorized commands.Recommendations
Apply patch adf2d9a09945fc98c85a2520a89f441d78b2dbd8 to resolve the issue.
Exploit
Fix
Command Injection
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Publint