Critical severity9.8NVD Advisory· Published Feb 10, 2021· Updated Jun 17, 2026
CVE-2021-27185
CVE-2021-27185
Description
The samba-client package before 4.0.0 for Node.js allows command injection because of the use of process.exec.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
samba-clientnpm | < 4.0.0 | 4.0.0 |
Affected products
3- Node.js/samba-clientdescription
- cpe:2.3:a:samba-client_project:samba-client:*:*:*:*:*:node.js:*:*Range: <4.0.0
Patches
Vulnerability mechanics
References
8- github.com/eflexsystems/node-samba-client/commit/5bc3bbad9b8d02243bc861a11ec73f788fbb1235nvdPatchThird Party AdvisoryWEB
- advisory.checkmarx.net/advisory/CX-2021-4302nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-r3j7-x2g5-9gx6ghsaADVISORY
- github.com/eflexsystems/node-samba-client/releases/tag/4.0.0nvdRelease NotesThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-27185ghsaADVISORY
- security.netapp.com/advisory/ntap-20210319-0002/nvdThird Party Advisory
- www.npmjs.com/package/samba-clientnvdProductThird Party AdvisoryWEB
- security.netapp.com/advisory/ntap-20210319-0002ghsaWEB
News mentions
0No linked articles in our index yet.