Arbitrary Code Execution in require-node
Critical severity
GitHub Reviewed
Published
Sep 3, 2020
to the GitHub Advisory Database
•
Updated Jan 12, 2023
Description
Reviewed
Aug 31, 2020
Published to the GitHub Advisory Database
Sep 3, 2020
Last updated
Jan 12, 2023
Versions of
require-node
prior to 1.3.4 for 1.x and 2.0.4 for 2.x are vulnerable to Arbitrary Code Execution. The package fails to sanitize requests to therequire-node
endpoint, allowing attackers to execute arbitrary code in the server through the injection of OS commands in the request body.Recommendation
References