OSV 1.4.0 · github-reviewed · 修改于 2022-07-06 02:01
发布时间
2021-03-20 05:19
GitHub 审查时间
2021-03-17 06:24
NVD 发布时间
2021-03-16 01:15
源文件
advisories/github-reviewed/2021/03/GHSA-qc65-cgvr-93p6/GHSA-qc65-cgvr-93p6.json
This affects all versions of package kill-process-by-name. If (attacker-controlled) user input is given, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization in the index.js file.