OS Command Injection in node-opencv
Critical severity
GitHub Reviewed
Published
Oct 12, 2021
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Reviewed
Oct 7, 2021
Published to the GitHub Advisory Database
Oct 12, 2021
Last updated
Jan 9, 2023
utils/find-opencv.js in node-opencv (aka OpenCV bindings for Node.js) prior to 6.1.0 is vulnerable to Command Injection. It does not validate user input allowing attackers to execute arbitrary commands.
References