{"id":"GHSA-gjx4-2c7g-fm94","summary":"screenshot-desktop vulnerable to command Injection via `format` option","details":"## Impact\nThis vulnerability is a **command injection** issue.  \nWhen user-controlled input is passed into the `format` option of the screenshot function, it is interpolated into a shell command without sanitization.  \nAn attacker can craft malicious input such as:\n\n    { format: \"; echo vulnerable \u003e /tmp/hello;\" }\n\nThis results in arbitrary command execution with the privileges of the calling process.\n\n**Who is impacted:**  \nAny application that accepts untrusted input and forwards it directly (or indirectly) into the `format` option is affected. If the library is used in a server-side context (e.g., API endpoints, web services), attackers may be able to exploit this **remotely and without authentication**, leading to full compromise of confidentiality, integrity, and availability.\n\n**CVSS v3.1 Base Score:** 9.8 (Critical)  \n`CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H`\n\n\n## Patches\nThe issue has been patched in **version 1.15.2**.  \nAll users are strongly recommended to upgrade to **1.15.2 or later**.  \nAll earlier versions are vulnerable.\n\n\n\n## Workarounds\nIf upgrading is not immediately possible, developers should:\n- **Strictly validate or whitelist** acceptable `format` values (e.g., `\"jpeg\"`, `\"png\"`, `\"webp\"`).\n- **Reject or sanitize** any unexpected input before passing it to the library.\n- Avoid allowing user-controlled data to reach the `format` option.\n\n\n\n## References\n- [CWE-78: OS Command Injection](https://cwe.mitre.org/data/definitions/78.html)  \n- [OWASP: Command Injection](https://owasp.org/www-community/attacks/Command_Injection)","aliases":["CVE-2025-55294"],"modified":"2025-08-19T20:42:37.558563Z","published":"2025-08-19T20:17:45Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2025-08-19T20:17:45Z","nvd_published_at":"2025-08-19T18:15:29Z","cwe_ids":["CWE-77"]},"references":[{"type":"WEB","url":"https://github.com/bencevans/screenshot-desktop/security/advisories/GHSA-gjx4-2c7g-fm94"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-55294"},{"type":"WEB","url":"https://github.com/bencevans/screenshot-desktop/commit/59c87b0c175eec76090e6ccde313f4fc5d569b78"},{"type":"PACKAGE","url":"https://github.com/bencevans/screenshot-desktop"}],"affected":[{"package":{"name":"screenshot-desktop","ecosystem":"npm","purl":"pkg:npm/screenshot-desktop"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.15.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-gjx4-2c7g-fm94/GHSA-gjx4-2c7g-fm94.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}