VYPR
Critical severityNVD Advisory· Published Apr 6, 2020· Updated Aug 4, 2024

CVE-2020-7631

CVE-2020-7631

Description

diskusage-ng through 0.2.4 contains a command injection flaw in the path argument, allowing arbitrary command execution.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

diskusage-ng through 0.2.4 contains a command injection flaw in the path argument, allowing arbitrary command execution.

Description

The diskusage-ng npm package (versions < 1.0.0) suffers from a command injection vulnerability. The path argument passed to the library is processed without any sanitization, enabling an attacker to inject arbitrary shell commands. The issue originates in the lib/posix.js file, where user-supplied input is directly used in a system command [1][2][3].

Exploitation

An attacker can exploit this flaw by providing a specially crafted string as the path argument. For example, a proof-of-concept shown in the advisory uses "&touch Song" as part of the path array to execute the touch Song command. No authentication is required, as the attack surface is the application’s input that passes user-controlled data to the vulnerable function [1].

Impact

Successful exploitation allows an attacker to execute arbitrary operating system commands with the privileges of the Node.js process. This can lead to data exfiltration, system compromise, or lateral movement within the network [1].

Mitigation

The vulnerability has been fixed in version 1.0.0 of diskusage-ng. Users should upgrade immediately. No workarounds are documented [1].

AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
diskusage-ngnpm
<= 0.2.4

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.