OSV 1.4.0 · github-reviewed · 修改于 2023-09-12 02:33
发布时间
2019-09-12 07:03
GitHub 审查时间
2019-09-04 22:29
NVD 发布时间
—
源文件
advisories/github-reviewed/2019/09/GHSA-xf27-jqwv-gf3r/GHSA-xf27-jqwv-gf3r.json
Versions of larvitbase-api prior to 0.5.4 are vulnerable to an Unintended Require. The package exposes an API endpoint and passes a GET parameter unsanitized to an require() call. This allows attackers to execute any .js file in the same folder as the server is running.
Upgrade to version 0.5.4 or later.