Skip to content
This repository has been archived by the owner on Nov 13, 2021. It is now read-only.

arbitrary shell execution

Critical
asdfugil published GHSA-8xwp-r7pj-cgw3 Mar 25, 2020

Package

nick-chan-bot

Affected versions

> 1.0.0-beta

Patched versions

1.0.1-beta

Description

This is a vulnerability in the npm command

Impact

This allows arbitrary shell execution,which can compromise the bot

Workaround

Delete ./commands/npm.js.

Severity

Critical

CVE ID

CVE-2020-5282

Weaknesses

No CWEs