All versions including 0.0.4 of lsof npm module are vulnerable to Command Injection. Every exported method used by the package uses the exec function to parse user input.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-0886 All versions including 0.0.4 of lsof npm module are vulnerable to Command Injection. Every exported method used by the package uses the exec function to parse user input.
Github GHSA Github GHSA GHSA-whq6-mj2r-mjqc OS Command Injection in lsof
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: snyk

Published:

Updated: 2024-08-04T22:32:02.059Z

Reserved: 2019-04-03T00:00:00

Link: CVE-2019-10783

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-01-29T22:15:11.580

Modified: 2024-11-21T04:19:54.783

Link: CVE-2019-10783

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses