VYPR

npm package

keep-module-latest

pkg:npm/keep-module-latest

Vulnerabilities (1)

  • CVE-2023-26128May 27, 2023
    affected <= 1.0.1

    All versions of the package keep-module-latest are vulnerable to Command Injection due to missing input sanitization or other checks and sandboxes being employed to the installModule function. **Note:** To execute the code snippet and potentially exploit the vulnerability, the