VYPR
Critical severity9.8NVD Advisory· Published Aug 29, 2022· Updated Jun 17, 2026

CVE-2022-21165

CVE-2022-21165

Description

All versions of package font-converter are vulnerable to Arbitrary Command Injection due to missing sanitization of input that potentially flows into the child_process.exec() function.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
font-converternpm
<= 1.1.1

Affected products

5
  • font-converter/font-converterdescription
  • ghsa-coords
    Range: <= 1.1.1
  • cpe:2.3:a:font_converter_project:font_converter:1.0.0:*:*:*:*:node.js:*:*+ 2 more
    • cpe:2.3:a:font_converter_project:font_converter:1.0.0:*:*:*:*:node.js:*:*
    • cpe:2.3:a:font_converter_project:font_converter:1.1.0:*:*:*:*:node.js:*:*
    • cpe:2.3:a:font_converter_project:font_converter:1.1.1:*:*:*:*:node.js:*:*

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.