Critical severity9.8NVD Advisory· Published Feb 28, 2020· Updated Jun 17, 2026
CVE-2019-10804
CVE-2019-10804
Description
serial-number through 1.3.0 allows execution of arbritary commands. The "cmdPrefix" argument in serialNumber function is used by the "exec" function without any validation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
serial-numbernpm | <= 1.3.0 | — |
Affected products
3- serial-number/serial-numberdescription
- cpe:2.3:a:serial-number_project:serial-number:*:*:*:*:*:node.js:*:*Range: <=1.3.0
Patches
Vulnerability mechanics
References
4- snyk.io/vuln/SNYK-JS-SERIALNUMBER-559010nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-3fw4-4h3m-892hghsaADVISORY
- github.com/es128/serial-number/blob/master/index.jsnvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2019-10804ghsaADVISORY
News mentions
0No linked articles in our index yet.