High severity8.8NVD Advisory· Published Jun 2, 2022· Updated Jun 17, 2026
CVE-2021-34078
CVE-2021-34078
Description
lifion-verify-dependencies through 1.1.0 is vulnerable to OS command injection via a crafted dependency name on the scanned project's package.json file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
lifion-verify-depsnpm | < 1.2.0 | 1.2.0 |
Affected products
3- cpe:2.3:a:adp:lifion-verifiy-dependencies:*:*:*:*:*:node.js:*:*Range: <1.2.0
- lifion/lifion-verify-dependenciesdescription
Patches
Vulnerability mechanics
References
4- github.com/lifion/lifion-verify-deps/commit/be1133d5b78e3caa0004fa60207013dca4e1bf38nvdPatchThird Party AdvisoryWEB
- advisory.checkmarx.net/advisory/CX-2021-4785nvdExploitPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-rphm-c8gw-3r38ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-34078ghsaADVISORY
News mentions
0No linked articles in our index yet.