Critical severity9.8NVD Advisory· Published Dec 22, 2021· Updated Jun 17, 2026
CVE-2021-45459
CVE-2021-45459
Description
lib/cmd.js in the node-windows package before 1.0.0-beta.6 for Node.js allows command injection via the PID parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
node-windowsnpm | < 1.0.0-beta.6 | 1.0.0-beta.6 |
Affected products
8cpe:2.3:a:node-windows_project:node-windows:*:*:*:*:*:node.js:*:*+ 5 more
- cpe:2.3:a:node-windows_project:node-windows:*:*:*:*:*:node.js:*:*range: <=0.1.14
- cpe:2.3:a:node-windows_project:node-windows:1.0.0:beta1:*:*:*:node.js:*:*
- cpe:2.3:a:node-windows_project:node-windows:1.0.0:beta2:*:*:*:node.js:*:*
- cpe:2.3:a:node-windows_project:node-windows:1.0.0:beta3:*:*:*:node.js:*:*
- cpe:2.3:a:node-windows_project:node-windows:1.0.0:beta4:*:*:*:node.js:*:*
- cpe:2.3:a:node-windows_project:node-windows:1.0.0:beta5:*:*:*:node.js:*:*
- node-windows/node-windowsdescription
Patches
Vulnerability mechanics
References
8- github.com/coreybutler/node-windows/compare/1.0.0-beta.5...1.0.0-beta.6nvdPatchThird Party AdvisoryWEB
- github.com/dwisiswant0/advisory/issues/4nvdExploitIssue TrackingPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-53xv-c2hx-5w6qghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-45459ghsaADVISORY
- security.netapp.com/advisory/ntap-20220107-0004/nvdThird Party Advisory
- advisory.dw1.io/4ghsaWEB
- github.com/coreybutler/node-windows/commit/a379d31366edbd7a672a981e6c09e185ab448dd3ghsaWEB
- security.netapp.com/advisory/ntap-20220107-0004ghsaWEB
News mentions
0No linked articles in our index yet.