{"id":"GHSA-28xh-wpgr-7fm8","summary":"Command Injection in open","details":"Versions of `open` before 6.0.0 are vulnerable to command injection when unsanitized user input is passed in.\n\nThe package does come with the following warning in the readme:\n\n```\nThe same care should be taken when calling open as if you were calling child_process.exec directly. If it is an executable it will run in a new shell.\n```\n\n\n## Recommendation\n\n`open` is now the deprecated `opn` package. Upgrading to the latest version is likely have unwanted effects since it now has a very different API but will prevent this vulnerability.","modified":"2020-08-31T18:31:51Z","published":"2019-06-20T15:35:49Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-77"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2019-06-20T15:35:06Z"},"references":[{"type":"WEB","url":"https://github.com/pwnall/node-open/issues/68"},{"type":"WEB","url":"https://github.com/pwnall/node-open/issues/69"},{"type":"WEB","url":"https://hackerone.com/reports/319473"},{"type":"WEB","url":"https://www.npmjs.com/advisories/663"}],"affected":[{"package":{"name":"open","ecosystem":"npm","purl":"pkg:npm/open"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"6.0.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/06/GHSA-28xh-wpgr-7fm8/GHSA-28xh-wpgr-7fm8.json"}}],"schema_version":"1.9.0"}