{"id":"GHSA-8j6j-4h2c-c65p","aliases":[],"url":"https://o3.security/vulnerability/GHSA-8j6j-4h2c-c65p","summary":"Arbitrary Code Execution in require-node","details":"Versions of `require-node` prior to 1.3.4 for 1.x and 2.0.4 for 2.x are vulnerable to Arbitrary Code Execution. The package fails to sanitize requests to the `require-node` endpoint, allowing attackers to execute arbitrary code in the server through the injection of OS commands in the request body.\n\n\n## Recommendation\n\n- If you are using 1.x, upgrade to version 1.3.4 or later.\n- If you are using 2.x, upgrade to version 2.0.4 or later.","published":"2020-09-03T17:02:52Z","modified":"2020-08-31T18:44:11Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"require-node","fixedVersion":"1.3.4"},{"ecosystem":"npm","name":"require-node","fixedVersion":"2.0.4"}],"fix":null,"references":[{"type":"WEB","url":"https://www.npmjs.com/advisories/1015"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2020-08-31T18:44:11Z"}}