PT-2023-20508 · Unknown · Keep-Module-Latest
Johns Hopkins
·
Published
2023-05-27
·
Updated
2025-01-13
·
CVE-2023-26128
CVSS v3.1
8.4
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
keep-module-latest versions all
Description
The issue arises due to missing input sanitization or other checks and sandboxes being employed to the
installModule function, leading to Command Injection. To potentially exploit this, an attacker needs the ability to run Node.js code within the target environment, typically requiring some level of access to the system or application hosting the Node.js environment.Recommendations
For all versions, consider disabling the
installModule function until a patch is available to prevent potential Command Injection attacks. Restrict access to the Node.js environment to minimize the risk of exploitation. Avoid using the installModule function in sensitive operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
OS Command Injection
RCE
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Keep-Module-Latest