{"id":"GHSA-mm4f-47ch-f7hx","summary":"Arbitrary code execution in kill-by-port","details":"This affects the package kill-by-port before 0.0.2. If (attacker-controlled) user input is given to the killByPort function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.","aliases":["CVE-2021-23363","SNYK-JS-KILLBYPORT-1078531"],"modified":"2026-09-10T03:49:03.753576827Z","published":"2021-04-13T15:32:43Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2021-03-31T20:18:57Z","nvd_published_at":"2021-03-30T15:15:00Z","cwe_ids":["CWE-77"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-23363"},{"type":"WEB","url":"https://github.com/GuyMograbi/kill-by-port/commit/ea5b1f377e196a4492e05ff070eba8b30b7372c4"},{"type":"PACKAGE","url":"https://github.com/GuyMograbi/kill-by-port"},{"type":"WEB","url":"https://github.com/GuyMograbi/kill-by-port/blob/16dcbe264b6b4a5ecf409661b42836dd286fd43f/index.js#23L8"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-KILLBYPORT-1078531"}],"affected":[{"package":{"name":"kill-by-port","ecosystem":"npm","purl":"pkg:npm/kill-by-port"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.0.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/04/GHSA-mm4f-47ch-f7hx/GHSA-mm4f-47ch-f7hx.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"}]}