CVE-2022-25923

Published
View on NVD ↗
CVSS v3
7.4
HIGH
CVSS v2
N/A
Affected
1
PROJECT

Description

Versions of the package exec-local-bin before 1.2.0 are vulnerable to Command Injection via the theProcess() functionality due to improper user-input sanitization.

Helps you run local node executables in node
GitHubGitHub
1