Description
Versions of require-node
prior to 1.3.4 for 1.x and 2.0.4 for 2.x are vulnerable to Arbitrary Code Execution. The package fails to sanitize requests to the require-node
endpoint, allowing attackers to execute arbitrary code in the server through the injection of OS commands in the request body.
Recommendation
Update the require-node
package to the latest compatible version. Followings are version details:
Affected version(s): **>= 2.0.0, < 2.0.4 < 1.3.4** Patched version(s): **2.0.4 1.3.4**
References
Related Issues
- tarteaucitron Cross-site Scripting (XSS) - CVE-2025-1467
- Cross site scripting in markdown-to-jsx - CVE-2024-21535
- uPlot Prototype Pollution vulnerability - CVE-2024-21489
- FUXA local file inclusion vulnerability - CVE-2023-31718
- Tags:
- npm
- require-node
Anything's wrong? Let us know Last updated on January 12, 2023