Vulnerabilities/

Pedroetb TTS-API OS Command Injection

Severity:
High

Description

A vulnerability has been found in pedroetb tts-api up to 2.1.4 and classified as critical. This vulnerability affects the function onSpeechDone of the file app.js. The manipulation leads to os command injection. Upgrading to version 2.2.0 is able to address this issue. The patch is identified as 29d9c25415911ea2f8b6de247cb5c4607d13d434.

Recommendation

Update the tts-api package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
tts-api
Anything's wrong? Let us know Last updated on December 28, 2023

This issue is available in SmartScanner Professional

See Pricing