{"id":"GHSA-xhjx-mfr6-9rr4","aliases":[],"url":"https://o3.security/vulnerability/GHSA-xhjx-mfr6-9rr4","summary":"Command Injection in samsung-remote","details":"Versions of `samsung-remote` before 1.3.5 are vulnerable to command injection. This vulnerability is exploitable if user input is passed into the `ip` option of the package constructor.\n\n\n## Recommendation\n\nUpdate to version 1.3.5 or later.","published":"2020-09-01T21:20:28Z","modified":"2020-08-31T18:33:52Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"samsung-remote","fixedVersion":"1.3.5"}],"fix":null,"references":[{"type":"WEB","url":"https://hackerone.com/reports/394294"},{"type":"WEB","url":"https://github.com/nodejs/security-wg/blob/master/vuln/npm/465.json"},{"type":"WEB","url":"https://www.npmjs.com/advisories/734"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2020-08-31T18:33:52Z"}}