Critical severity9.0NVD Advisory· Published Nov 22, 2021· Updated Jun 17, 2026
CVE-2021-23732
CVE-2021-23732
Description
This affects all versions of package docker-cli-js. If the command parameter of the Docker.command method can at least be partially controlled by a user, they will be in a position to execute any arbitrary OS commands on the host system.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
docker-cli-jsnpm | <= 2.8.0 | — |
Affected products
3- cpe:2.3:a:quobject:docker-cli-js:-:*:*:*:*:node.js:*:*
- docker-cli-js/docker-cli-jsdescription
Patches
Vulnerability mechanics
References
6- snyk.io/vuln/SNYK-JS-DOCKERCLIJS-1568516nvdExploitThird Party AdvisoryVDB EntryWEB
- github.com/advisories/GHSA-ff45-7prw-58vjghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-23732ghsaADVISORY
- security.netapp.com/advisory/ntap-20211223-0004/nvdThird Party Advisory
- github.com/Quobject/docker-cli-js/issues/22ghsaWEB
- github.com/Quobject/docker-cli-js/issues/22ghsaWEB
News mentions
0No linked articles in our index yet.