Critical severity10.0NVD Advisory· Published Jun 25, 2020· Updated Jun 17, 2026
CVE-2018-21268
CVE-2018-21268
Description
The traceroute (aka node-traceroute) package through 1.0.0 for Node.js allows remote command injection via the host parameter. This occurs because the Child.exec() method, which is considered to be not entirely safe, is used. In particular, an OS command can be placed after a newline character.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
traceroutenpm | <= 1.0.0 | — |
Affected products
3- cpe:2.3:a:traceroute_project:traceroute:*:*:*:*:*:node.js:*:*Range: <=1.0.0
- node-traceroute/node-traceroutedescription
Patches
Vulnerability mechanics
References
12- github.com/jaw187/node-traceroute/commit/b99ee024a01a40d3d20a92ad3769cc78a3f6386fnvdPatchThird Party AdvisoryWEB
- snyk.io/vuln/npm:traceroute:20160311nvdExploitThird Party AdvisoryWEB
- www.op-c.net/2020/06/17/shell-command-injection-through-traceroute-npm-package/nvdExploitThird Party Advisory
- github.com/advisories/GHSA-8j9v-qhp4-wv55ghsaADVISORY
- github.com/jaw187/node-traceroute/tagsnvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2018-21268ghsaADVISORY
- www.linkedin.com/posts/op-innovate_shell-command-injection-through-traceroute-activity-6678956453086191616-RcpynvdThird Party AdvisoryWEB
- www.npmjs.com/advisories/1465nvdThird Party AdvisoryWEB
- www.npmjs.com/package/traceroutenvdProductThird Party Advisory
- medium.com/@shay_62828/shell-command-injection-through-traceroute-npm-package-a4cf7b6553e3ghsaWEB
- www.op-c.net/2020/06/17/shell-command-injection-through-traceroute-npm-packageghsaWEB
- medium.com/%40shay_62828/shell-command-injection-through-traceroute-npm-package-a4cf7b6553e3nvd
News mentions
0No linked articles in our index yet.