Command Injection in kill-port
High severity
GitHub Reviewed
Published
Mar 25, 2019
to the GitHub Advisory Database
•
Updated Sep 8, 2023
Description
Published to the GitHub Advisory Database
Mar 25, 2019
Reviewed
Jun 16, 2020
Last updated
Sep 8, 2023
Versions of
kill-port
prior to 1.3.2 are vulnerable to Command Injection. The package does not validate user input on thekill
function. This may allow attackers to run arbitrary commands in the system if user input (such as the port number) is passed directly to the function.Recommendation
Upgrade to version 1.3.2 or later.
References