Critical severity9.8OSV Advisory· Published Mar 26, 2019· Updated Jun 17, 2026
CVE-2019-10061
CVE-2019-10061
Description
utils/find-opencv.js in node-opencv (aka OpenCV bindings for Node.js) prior to 6.1.0 is vulnerable to Command Injection. It does not validate user input allowing attackers to execute arbitrary commands.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
opencvnpm | < 6.1.0 | 6.1.0 |
Affected products
3- Range: v0.4.0, v3.0.0, v6.0.0
- cpe:2.3:a:node-opencv_project:node-opencv:*:*:*:*:*:node.js:*:*Range: <6.1.0
Patches
Vulnerability mechanics
References
6- github.com/peterbraden/node-opencv/commit/81a4b8620188e89f7e4fc985f3c89b58d4bcc86bnvdPatchThird Party AdvisoryWEB
- github.com/peterbraden/node-opencv/commit/aaece6921d7368577511f06c94c99dd4e9653563nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-mc7w-4cjf-c973ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-10061ghsaADVISORY
- www.npmjs.com/advisories/789nvdThird Party AdvisoryWEB
- www.npmjs.com/package/opencvghsaWEB
News mentions
0No linked articles in our index yet.