Critical severity9.8NVD Advisory· Published Feb 18, 2020· Updated Jun 17, 2026
CVE-2019-10791
CVE-2019-10791
Description
promise-probe before 0.10.0 allows remote attackers to perform a command injection attack. The file, outputFile and options functions can be controlled by users without any sanitization.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
promise-probenpm | < 0.1.10 | 0.1.10 |
Affected products
3- cpe:2.3:a:promise-probe_project:promise-probe:*:*:*:*:*:node.js:*:*Range: <0.10.0
- Snyk/promise-probev5Range: All versions prior to version 0.10.0
Patches
Vulnerability mechanics
References
5- snyk.io/vuln/SNYK-JS-PROMISEPROBE-546816nvdExploitPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-vmqq-7qvx-68qxghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-10791ghsaADVISORY
- github.com/dottgonzo/node-promise-probe/commit/0d9affb67fc1ad985903536d35372cf55efe5a45ghsaWEB
- github.com/dottgonzo/node-promise-probe/commit/0d9affb67fc1ad985903536d35372cf55efe5a45%2Cnvd
News mentions
0No linked articles in our index yet.