This affects the package node-notifier before 9.0.0. It allows an attacker to run arbitrary commands on Linux machines due to the options params not being sanitised when being passed an array.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: snyk
Published: 2020-12-11T09:55:13.720901Z
Updated: 2024-09-16T16:28:29.110Z
Reserved: 2020-01-21T00:00:00
Link: CVE-2020-7789
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2020-12-11T10:15:12.423
Modified: 2020-12-17T15:52:47.867
Link: CVE-2020-7789
Redhat