{"id":"GHSA-m7xq-8jp8-rj2c","summary":"Command injection in npm-dependency-versions","details":"The npm-dependency-versions package through 0.3.0 for Node.js allows command injection if an attacker is able to call dependencyVersions with a JSON object in which pkgs is a key, and there are shell metacharacters in a value.","aliases":["CVE-2022-29080"],"modified":"2023-11-08T04:09:08.005439Z","published":"2022-04-13T00:00:33Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2022-07-18T21:00:59Z","nvd_published_at":"2022-04-12T05:15:00Z","cwe_ids":["CWE-77"],"severity":"CRITICAL"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-29080"},{"type":"WEB","url":"https://github.com/barneycarroll/npm-dependency-versions/issues/6"},{"type":"PACKAGE","url":"https://github.com/barneycarroll/npm-dependency-versions"},{"type":"WEB","url":"https://www.npmjs.com/package/npm-dependency-versions"}],"affected":[{"package":{"name":"npm-dependency-versions","ecosystem":"npm","purl":"pkg:npm/npm-dependency-versions"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"0.3.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-m7xq-8jp8-rj2c/GHSA-m7xq-8jp8-rj2c.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}