Description
Versions of require-node prior to 1.3.4 for 1.x and 2.0.4 for 2.x are vulnerable to Arbitrary Code Execution. The package fails to sanitize requests to the require-node endpoint, allowing attackers to execute arbitrary code in the server through the injection of OS commands in the request body.
Recommendation
Update the require-node package to the latest compatible version. Followings are version details:
Affected version(s): **>= 2.0.0, < 2.0.4 < 1.3.4** Patched version(s): **2.0.4 1.3.4**
References
Related Issues
- Vega vulnerable to arbitrary code execution when clicking href links - Vulnerability
- Trix Editor Arbitrary Code Execution Vulnerability - CVE-2024-34341
- React Editable Json Tree vulnerable to arbitrary code execution via function parsing - CVE-2022-36010
- JSONPath Plus Remote Code Execution (RCE) Vulnerability - CVE-2024-21534
- Tags:
- npm
- require-node
Anything's wrong? Let us know Last updated on January 12, 2023