VYPR

npm package

pulverizr

pkg:npm/pulverizr

Vulnerabilities (1)

  • CVE-2020-7604Mar 15, 2020
    affected <= 0.7.0

    pulverizr through 0.7.0 allows execution of arbitrary commands. Within "lib/job.js", the variable "filename" can be controlled by the attacker. This function uses the variable "filename" to construct the argument of the exec call without any sanitization. In order to successfully