High severity7.4NVD Advisory· Published Jan 31, 2023· Updated Jun 17, 2026
CVE-2022-21129
CVE-2022-21129
Description
Versions of the package nemo-appium before 0.0.9 are vulnerable to Command Injection due to improper input sanitization in the 'module.exports.setup' function. Note: In order to exploit this vulnerability appium-running 0.1.3 has to be installed as one of nemo-appium dependencies.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
nemo-appiumnpm | < 0.0.9 | 0.0.9 |
Affected products
3- nemo-appium/nemo-appiumdescription
Patches
Vulnerability mechanics
References
5- github.com/paypal/nemo-appium/commit/aa271d36dd5c81baae3c43aa2616c84f0ee4195fnvdPatchThird Party AdvisoryWEB
- security.snyk.io/vuln/SNYK-JS-NEMOAPPIUM-3183747nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-c6rx-gxqv-vr5jghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-21129ghsaADVISORY
- github.com/paypal/nemo-appium/blob/master/index.js%23L27nvdBroken LinkWEB
News mentions
0No linked articles in our index yet.