VYPR
High severityNVD Advisory· Published Dec 21, 2022· Updated Apr 15, 2025

Command Injection

CVE-2022-24431

Description

All versions of package abacus-ext-cmdline are vulnerable to Command Injection via the execute function due to improper user-input sanitization.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

All versions of the abacus-ext-cmdline npm package are vulnerable to command injection via the execute function due to insufficient input sanitization.

Overview

CVE-2022-24431 affects all versions of the abacus-ext-cmdline npm package. The vulnerability is a command injection flaw in the execute function, which fails to properly sanitize user-supplied input before passing it to a system command [1][2]. This allows an attacker to inject arbitrary shell commands.

Exploitation

An attacker can exploit this vulnerability by providing a crafted string to the execute function. For example, the proof-of-concept demonstrates that passing "& touch JHU &" results in execution of the touch command [2]. No authentication is required if the attacker can control the input to this function, which may occur in applications that use the package to process user-provided command-line arguments.

Impact

Successful exploitation leads to arbitrary command execution with the privileges of the application or process that invokes the execute function. This can result in full system compromise, data exfiltration, or further lateral movement within the network.

Mitigation

As of the publication date, there is no patched version of abacus-ext-cmdline [2]. The package appears to be unmaintained. Users are advised to avoid using this package altogether or to implement strict input validation and sanitization as a workaround. Organizations should assess their exposure and consider replacing the package with a maintained alternative.

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
abacus-ext-cmdlinenpm
<= 0.0.6-dev.9

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.