High severity8.4NVD Advisory· Published May 27, 2023· Updated Jun 17, 2026
CVE-2023-26128
CVE-2023-26128
Description
All versions of the package keep-module-latest are vulnerable to Command Injection due to missing input sanitization or other checks and sandboxes being employed to the installModule function. Note: To execute the code snippet and potentially exploit the vulnerability, the attacker needs to have the ability to run Node.js code within the target environment. This typically requires some level of access to the system or application hosting the Node.js environment.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
keep-module-latestnpm | <= 1.0.1 | — |
Affected products
3- keep-module-latest/keep-module-latestdescription
- cpe:2.3:a:keep-module-latest_project:keep-module-latest:*:*:*:*:*:node.js:*:*
Patches
Vulnerability mechanics
References
4- security.snyk.io/vuln/SNYK-JS-KEEPMODULELATEST-3157165nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-wxrx-pc44-rcgcghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-26128ghsaADVISORY
- github.com/liujunyang/keep-module-latest/blob/master/index.js%23L50nvdBroken LinkWEB
News mentions
0No linked articles in our index yet.