{"id":"CVE-2021-34080","aliases":["GHSA-552j-pv39-f3jf"],"url":"https://o3.security/vulnerability/CVE-2021-34080","summary":"OS Command injection in ssl-utils","details":"OS Command Injection vulnerability in es128 ssl-utils 1.0.0 for Node.js allows attackers to execute arbitrary commands via unsanitized shell metacharacters provided to the createCertRequest() and the createCert() functions.","published":"2022-06-02T14:15:28.843Z","modified":"2026-07-08T22:14:07.368208Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"npm","name":"ssl-utils","fixedVersion":null}],"fix":null,"references":[{"type":"EVIDENCE","url":"https://advisory.checkmarx.net/advisory/CX-2021-4782"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T22:14:07.368208Z"}}