High severity8.1NVD Advisory· Published Jun 2, 2022· Updated Jun 17, 2026
CVE-2021-34083
CVE-2021-34083
Description
Google-it is a Node.js package which allows its users to send search queries to Google and receive the results in a JSON format. When using the 'Open in browser' option in versions up to 1.6.2, google-it will unsafely concat the result's link retrieved from google to a shell command, potentially exposing the server to RCE.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
google-itnpm | <= 1.6.2 | — |
Affected products
2- Google-it/Google-itdescription
Patches
Vulnerability mechanics
References
5- advisory.checkmarx.net/advisory/CX-2021-4777nvdExploitThird Party AdvisoryWEB
- github.com/PatNeedham/google-it/blob/v1.6.2/lib/googleIt.jsnvdExploitThird Party AdvisoryWEB
- github.com/PatNeedham/google-it/blob/v1.6.2/src/googleIt.jsnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-7xhv-mpjw-422fghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-34083ghsaADVISORY
News mentions
0No linked articles in our index yet.