Critical severityNVD Advisory· Published Feb 28, 2015· Updated Jun 17, 2026
CVE-2014-9682
CVE-2014-9682
Description
The dns-sync module before 0.1.1 for node.js allows context-dependent attackers to execute arbitrary commands via shell metacharacters in the first argument to the resolve API function.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
dns-syncnpm | < 0.1.1 | 0.1.1 |
Affected products
2Patches
Vulnerability mechanics
References
5News mentions
0No linked articles in our index yet.