PT-2023-20508 · Unknown · Keep-Module-Latest

Johns Hopkins

·

Published

2023-05-27

·

Updated

2025-01-13

·

CVE-2023-26128

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions keep-module-latest versions all
Description The issue arises due to missing input sanitization or other checks and sandboxes being employed to the installModule function, leading to Command Injection. To potentially exploit this, an attacker needs the ability to run Node.js code within the target environment, typically requiring some level of access to the system or application hosting the Node.js environment.
Recommendations For all versions, consider disabling the installModule function until a patch is available to prevent potential Command Injection attacks. Restrict access to the Node.js environment to minimize the risk of exploitation. Avoid using the installModule function in sensitive operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

RCE

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2023-26128
GHSA-WXRX-PC44-RCGC

Affected Products

Keep-Module-Latest