Critical severity9.8NVD Advisory· Published Jan 8, 2020· Updated Jun 17, 2026
CVE-2019-10778
CVE-2019-10778
Description
devcert-sanscache before 0.4.7 allows remote attackers to execute arbitrary code or cause a Command Injection via the exec function. The variable commonName controlled by user input is used as part of the exec function without any sanitization.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
devcert-sanscachenpm | < 0.4.7 | 0.4.7 |
Affected products
3- cpe:2.3:a:devcert-sanscache_project:devcert-sanscache:*:*:*:*:*:*:*:*Range: <0.4.7
- devcert-sanscache/devcert-sanscachedescription
Patches
Vulnerability mechanics
References
4- snyk.io/vuln/SNYK-JS-DEVCERTSANSCACHE-540926nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-4gp3-p7ph-x2jrghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-10778ghsaADVISORY
- github.com/guybedford/devcert/commit/571f4e6d077f7f21c6aed655ae380d85a7a5d3b8ghsaWEB
News mentions
0No linked articles in our index yet.