Critical severity9.8NVD Advisory· Published Sep 7, 2018· Updated Jun 17, 2026
CVE-2018-16460
CVE-2018-16460
Description
A command Injection in ps package versions <1.0.0 for Node.js allowed arbitrary commands to be executed when attacker controls the PID.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
psnpm | < 1.0.0 | 1.0.0 |
Affected products
3- https://github.com/UmbraEngineering/psv5Range: 1.0.0
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-cfhg-9x44-78h2ghsaADVISORY
- hackerone.com/reports/390848nvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2018-16460ghsaADVISORY
- github.com/nodejs/security-wg/blob/master/vuln/npm/470.jsonghsaWEB
- www.npmjs.com/advisories/728ghsaWEB
News mentions
0No linked articles in our index yet.