Command Injection
Description
Command injection vulnerability in the freediskspace npm package due to improper neutralization of arguments in line 71 of freediskspace.js.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Command injection vulnerability in the freediskspace npm package due to improper neutralization of arguments in line 71 of freediskspace.js.
Vulnerability
Overview
The freediskspace npm package, in all versions, contains a command injection vulnerability stemming from improper neutralization of arguments in line 71 of freediskspace.js [1][2]. The package fails to sanitize user-supplied input before passing it to a system command, allowing an attacker to inject arbitrary shell commands.
Exploitation
An attacker can exploit this vulnerability by providing a crafted argument to the freediskspace function. No authentication is required if the application exposes this function to untrusted input, such as through a web API or command-line interface. The attacker only needs to control the argument value that is passed to the vulnerable line [2].
Impact
Successful exploitation allows an attacker to execute arbitrary commands on the host system with the privileges of the Node.js process. This can lead to full system compromise, data exfiltration, or further lateral movement within the network [2].
Mitigation
As of the publication date, there is no patched version of freediskspace available [2]. The only mitigation is to avoid using the package or to ensure that any input passed to it is strictly validated and sanitized before use. The vulnerability is listed in the Snyk database and has been assigned a CVSS score [1].
AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
freediskspacenpm | <= 1.2.0 | — |
Affected products
2- freediskspace/freediskspacedescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/advisories/GHSA-4gfq-6m28-m5mgghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-7775ghsaADVISORY
- snyk.io/vuln/SNYK-JS-FREEDISKSPACE-1040716ghsax_refsource_MISCWEB
News mentions
0No linked articles in our index yet.