{"id":"GHSA-hmw2-mvvh-jf5j","summary":"OS Command Injection in enpeem","details":"enpeem through 2.2.0 allows execution of arbitrary commands. The &quot;options.dir&quot; argument is provided to the &quot;exec&quot; function without any sanitization.","aliases":["CVE-2019-10801","SNYK-JS-ENPEEM-559007"],"modified":"2026-09-10T03:49:03.400993172Z","published":"2021-04-13T15:22:47Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2021-04-08T22:25:20Z","nvd_published_at":"2020-02-28T21:15:00Z","cwe_ids":["CWE-78"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-10801"},{"type":"WEB","url":"https://github.com/balderdashy/enpeem/blob/master/index.js#L114"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-ENPEEM-559007"}],"affected":[{"package":{"name":"enpeem","ecosystem":"npm","purl":"pkg:npm/enpeem"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"2.2.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/04/GHSA-hmw2-mvvh-jf5j/GHSA-hmw2-mvvh-jf5j.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}