{"id":"GHSA-ff45-7prw-58vj","summary":"OS Command injection in docker-cli-js","details":"# Withdrawn\n\nAfter reviewing this CVE, and [this response from the maintainer](https://github.com/Quobject/docker-cli-js/issues/22#issuecomment-967760940), we have withdrawn this advisory.\n\n# Original CVE description\n\nThis affects all versions of package docker-cli-js. If the command parameter of the Docker.command method can at least be partially controlled by a user, they will be in a position to execute any arbitrary OS commands on the host system. ","aliases":["CVE-2021-23732"],"modified":"2026-09-10T03:49:16.287405584Z","published":"2021-12-02T17:51:22Z","withdrawn":"2021-11-29T18:17:00Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2021-11-30T14:50:39Z","nvd_published_at":"2021-11-22T17:15:00Z","cwe_ids":["CWE-78"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-23732"},{"type":"WEB","url":"https://github.com/Quobject/docker-cli-js/issues/22"},{"type":"WEB","url":"https://github.com/Quobject/docker-cli-js/issues/22#issuecomment-967760940"},{"type":"PACKAGE","url":"https://github.com/Quobject/docker-cli-js"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-DOCKERCLIJS-1568516"}],"affected":[{"package":{"name":"docker-cli-js","ecosystem":"npm","purl":"pkg:npm/docker-cli-js"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"2.8.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/12/GHSA-ff45-7prw-58vj/GHSA-ff45-7prw-58vj.json"}}],"schema_version":"1.9.0"}