global-modules-path Command Injection vulnerability
Critical severity
GitHub Reviewed
Published
Jan 13, 2023
to the GitHub Advisory Database
•
Updated Jan 28, 2023
Description
Published by the National Vulnerability Database
Jan 13, 2023
Published to the GitHub Advisory Database
Jan 13, 2023
Reviewed
Jan 13, 2023
Last updated
Jan 28, 2023
Versions of the package global-modules-path before 3.0.0 are vulnerable to Command Injection due to missing input sanitization or other checks and sandboxes being employed to the getPath function.
References