Critical severity9.8NVD Advisory· Published Apr 6, 2020· Updated Jun 17, 2026
CVE-2020-7631
CVE-2020-7631
Description
diskusage-ng through 0.2.4 is vulnerable to Command Injection.It allows execution of arbitrary commands via the path argument.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
diskusage-ngnpm | <= 0.2.4 | — |
Affected products
3- cpe:2.3:a:diskusage-ng_project:diskusage-ng:*:*:*:*:*:node.js:*:*Range: <=0.2.4
- diskusage-ng/diskusage-ngdescription
Patches
Vulnerability mechanics
References
4- github.com/iximiuz/node-diskusage-ng/blob/master/lib/posix.jsnvdExploitThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JS-DISKUSAGENG-564425nvdExploitWEB
- github.com/advisories/GHSA-3269-x4pw-vffgghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-7631ghsaADVISORY
News mentions
0No linked articles in our index yet.