{"id":"GHSA-8j6j-4h2c-c65p","summary":"Arbitrary Code Execution in require-node","details":"Versions of `require-node` prior to 1.3.4 for 1.x and 2.0.4 for 2.x are vulnerable to Arbitrary Code Execution. The package fails to sanitize requests to the `require-node` endpoint, allowing attackers to execute arbitrary code in the server through the injection of OS commands in the request body.\n\n\n## Recommendation\n\n- If you are using 1.x, upgrade to version 1.3.4 or later.\n- If you are using 2.x, upgrade to version 2.0.4 or later.","modified":"2020-08-31T18:44:11Z","published":"2020-09-03T17:02:52Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2020-08-31T18:44:11Z","nvd_published_at":null,"cwe_ids":["CWE-78"],"severity":"CRITICAL"},"references":[{"type":"WEB","url":"https://www.npmjs.com/advisories/1015"}],"affected":[{"package":{"name":"require-node","ecosystem":"npm","purl":"pkg:npm/require-node"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.3.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-8j6j-4h2c-c65p/GHSA-8j6j-4h2c-c65p.json"}},{"package":{"name":"require-node","ecosystem":"npm","purl":"pkg:npm/require-node"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.0.0"},{"fixed":"2.0.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-8j6j-4h2c-c65p/GHSA-8j6j-4h2c-c65p.json"}}],"schema_version":"1.9.0"}