High severity7.4NVD Advisory· Published Jan 4, 2023· Updated Jun 17, 2026
CVE-2022-25926
CVE-2022-25926
Description
Versions of the package window-control before 1.4.5 are vulnerable to Command Injection via the sendKeys function, due to improper input sanitization.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
window-controlnpm | < 1.4.5 | 1.4.5 |
Affected products
3- cpe:2.3:a:window-control_project:window-control:*:*:*:*:*:node.js:*:*Range: <1.4.5
- window-control/window-controldescription
Patches
Vulnerability mechanics
References
5- github.com/bruno-robert/window-control/commit/075c854534a749d887655a906759f5a7eee95173nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-9mjx-wfqp-j5phghsaADVISORY
- github.com/bruno-robert/window-control/releases/tag/v1.4.5nvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-25926ghsaADVISORY
- security.snyk.io/vuln/SNYK-JS-WINDOWCONTROL-3186345nvdThird Party AdvisoryWEB
News mentions
0No linked articles in our index yet.