All versions including 0.0.4 of lsof npm module are vulnerable to Command Injection. Every exported method used by the package uses the exec function to parse user input.
References
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: snyk

Published: 2020-01-29T21:07:28

Updated: 2024-08-04T22:32:02.059Z

Reserved: 2019-04-03T00:00:00

Link: CVE-2019-10783

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-01-29T22:15:11.580

Modified: 2020-08-24T17:37:01.140

Link: CVE-2019-10783

cve-icon Redhat

No data.