balderdashy/enpeem

balderdashy/enpeem

Releases8
Frequency4 months 3 weeks
Last Release
Stars19
Lightweight wrapper for accessing npm programmatically (alternative to adding `npm` as a dependency)

CVE History

CVEPublishedCVSS v3CVSS v2
9.8 CRITICAL7.5 HIGH

enpeem through 2.2.0 allows execution of arbitrary commands. The "options.dir" argument is provided to the "exec" function without any sanitization.