Medium severity6.3OSV Advisory· Published Mar 31, 2021· Updated Jun 17, 2026
CVE-2021-23348
CVE-2021-23348
Description
This affects the package portprocesses before 1.0.5. If (attacker-controlled) user input is given to the killProcess function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
portprocessesnpm | < 1.0.5 | 1.0.5 |
Affected products
3- Range: v1.0.0, v1.0.1, v1.0.2, …
- cpe:2.3:a:portprocesses_project:portprocesses:*:*:*:*:*:node.js:*:*Range: <1.0.5
Patches
Vulnerability mechanics
References
6- github.com/rrainn/PortProcesses/commit/86811216c9b97b01b5722f879f8c88a7aa4214e1nvdPatchThird Party AdvisoryWEB
- github.com/rrainn/PortProcesses/security/advisories/GHSA-vm67-7vmg-66vmnvdExploitThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JS-PORTPROCESSES-1078536nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-vm67-7vmg-66vmghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-23348ghsaADVISORY
- github.com/rrainn/PortProcesses/blob/fffceb09aff7180afbd0bd172e820404b33c8299/index.js%23L23nvdBroken LinkWEB
News mentions
0No linked articles in our index yet.