{"id":"CVE-2019-10801","details":"enpeem through 2.2.0 allows execution of arbitrary commands. The \"options.dir\" argument is provided to the \"exec\" function without any sanitization.","aliases":["GHSA-hmw2-mvvh-jf5j","SNYK-JS-ENPEEM-559007"],"modified":"2026-07-09T01:25:16.403893Z","published":"2020-02-28T21:15:12.867Z","references":[{"type":"ADVISORY","url":"https://github.com/balderdashy/enpeem/blob/master/index.js#L114"},{"type":"EVIDENCE","url":"https://snyk.io/vuln/SNYK-JS-ENPEEM-559007"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/balderdashy/enpeem","events":[{"introduced":"0"},{"last_affected":"06fda9b85c3a45dff84da940e355fc11cb53ecc8"}],"database_specific":{"cpe":"cpe:2.3:a:enpeem_project:enpeem:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"2.2.0"}],"source":"CPE_RANGE"}}],"versions":["v2.2.0","v2.1.0","v2.0.1","v2.0.0","v1.0.0","v0.2.0","v0.1.1","v0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-10801.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}