VYPR
High severityNVD Advisory· Published May 27, 2023· Updated Jan 13, 2025

CVE-2023-26128

CVE-2023-26128

Description

All versions of keep-module-latest are vulnerable to command injection via the installModule function, allowing arbitrary command execution if Node.js code can be run.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

All versions of keep-module-latest are vulnerable to command injection via the installModule function, allowing arbitrary command execution if Node.js code can be run.

The package keep-module-latest is vulnerable to command injection in all versions due to insufficient input sanitization in the installModule function. The function does not validate or sanitize the moduleName parameter before passing it to a command execution context, enabling injection of arbitrary commands [1][3].

To exploit the vulnerability, an attacker must have the ability to run Node.js code within the target environment. This typically requires some level of access to the system or application hosting the Node.js runtime. The injection occurs via the moduleName parameter, as demonstrated in the proof-of-concept: root({"moduleName":"& touch JHU"}) [3].

Successful exploitation allows an attacker to execute arbitrary commands on the underlying operating system, potentially leading to full system compromise, data exfiltration, or further lateral movement within the network.

As of the publication date, there is no fixed version available for keep-module-latest. The only mitigation is to avoid using the package or to ensure that untrusted users cannot control the moduleName parameter [3].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
keep-module-latestnpm
<= 1.0.1

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.