PT-2020-21411 · Node.Js · Express

Published

2020-09-02

·

Updated

2020-09-02

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions experss (affected versions not specified)
Description The issue concerns a typosquatted package that tracked users who installed it by mistake, thinking it was a similarly named popular package. It uploaded various information to a remote server, including the downloaded package name, the intended package name, the Node version, and whether the process was running with sudo privileges. There is no indication of further compromise.
Recommendations Remove the experss package from your dependencies and ensure that package names are typed correctly during installation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-MMPH-WP49-R48H

Affected Products

Express