CVE-2018-16462
CRITICALapex-publish-static-files < 2.0.1 - OS Command Injection via Maliciously Crafted Argument
Title source: llmDescription
A command injection vulnerability in the apex-publish-static-files npm module version <2.0.1 which allows arbitrary shell command execution through a maliciously crafted argument.
References (1)
Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://hackerone.com/reports/405694
Scores
CVSS v3
10.0
EPSS
0.0699
EPSS Percentile
93.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Details
CWE
CWE-77
CWE-78
Status
published
Products (2)
apex-publish-static-files_project/apex-publish-static-files
< 2.0.1
npm/apex-publish-static-files
0 - 2.0.1npm
Published
Oct 30, 2018
Tracked Since
Feb 18, 2026