{"id":"CVE-2021-45459","aliases":["GHSA-53xv-c2hx-5w6q"],"url":"https://o3.security/vulnerability/CVE-2021-45459","summary":"Command Injection in node-windows","details":"lib/cmd.js in the node-windows package before 1.0.0-beta.6 for Node.js allows command injection via the PID parameter.","published":"2021-12-22T06:15:07.130Z","modified":"2026-07-08T06:02:07.262946194Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"npm","name":"node-windows","fixedVersion":"1.0.0-beta.6"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20220107-0004/"},{"type":"FIX","url":"https://github.com/coreybutler/node-windows/compare/1.0.0-beta.5...1.0.0-beta.6"},{"type":"FIX","url":"https://github.com/dwisiswant0/advisory/issues/4"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T06:02:07.262946194Z"}}