Critical severity9.8NVD Advisory· Published Apr 12, 2022· Updated Jun 17, 2026
CVE-2022-29080
CVE-2022-29080
Description
The npm-dependency-versions package through 0.3.0 for Node.js allows command injection if an attacker is able to call dependencyVersions with a JSON object in which pkgs is a key, and there are shell metacharacters in a value.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
npm-dependency-versionsnpm | <= 0.3.0 | — |
Affected products
2- npm-dependency-versions/npm-dependency-versionsdescription
Patches
Vulnerability mechanics
References
4- github.com/barneycarroll/npm-dependency-versions/issues/6nvdExploitIssue TrackingThird Party AdvisoryWEB
- github.com/advisories/GHSA-m7xq-8jp8-rj2cghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-29080ghsaADVISORY
- www.npmjs.com/package/npm-dependency-versionsnvdProductThird Party AdvisoryWEB
News mentions
0No linked articles in our index yet.