CVE-2021-34082

CRITICAL

proctree < 0.1.1 - OS Command Injection via fix Function

Title source: llm
STIX 2.1

Description

OS Command Injection vulnerability in allenhwkim proctree through 0.1.1 and commit 0ac10ae575459457838f14e21d5996f2fa5c7593 for Node.js, allows attackers to execute arbitrary commands via the fix function.

References (2)

Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://advisory.checkmarx.net/advisory/CX-2021-4783

Scores

CVSS v3 9.8
EPSS 0.0488
EPSS Percentile 91.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (2)
npm/proctree 0npm
proctree_project/proctree < 0.1.1
Published Jun 02, 2022
Tracked Since Feb 18, 2026