CVE-2022-21191

HIGH

global-modules-path < 3.0.0 - OS Command Injection via getPath Function

Title source: llm
STIX 2.1

Description

Versions of the package global-modules-path before 3.0.0 are vulnerable to Command Injection due to missing input sanitization or other checks and sandboxes being employed to the getPath function.

Scores

CVSS v3 7.4
EPSS 0.0065
EPSS Percentile 71.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78 CWE-77
Status published
Products (2)
global-modules-path_project/global-modules-path < 3.0.0
npm/global-modules-path 0 - 3.0.0npm
Published Jan 13, 2023
Tracked Since Feb 18, 2026