Description
Versions of the package global-modules-path before 3.0.0 are vulnerable to Command Injection due to missing input sanitization or other checks and sandboxes being employed to the getPath function.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0565 | global-modules-path Command Injection vulnerability |
Github GHSA |
GHSA-vvj3-85vf-fgmw | global-modules-path Command Injection vulnerability |
References
History
Fri, 04 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2025-04-04T14:55:31.631Z
Reserved: 2022-02-24T11:58:23.980Z
Link: CVE-2022-21191
Updated: 2024-08-03T02:31:58.937Z
Status : Modified
Published: 2023-01-13T05:15:19.150
Modified: 2025-04-04T15:15:42.860
Link: CVE-2022-21191
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA