CVE-2021-23352

Published
View on NVD ↗
CVSS v3
8.6
HIGH
CVSS v2
7.5
HIGH
Affected
1
PROJECT

Description

This affects the package madge before 4.0.1. It is possible to specify a custom Graphviz path via the graphVizPath option parameter which when the .image(), .svg() or .dot() functions are called, is executed by the childprocess.exec function.

Create graphs from your CommonJS, AMD or ES6 module dependencies
GitHubGitHub
10.1K