{"id":"GHSA-95rp-6gqp-6622","summary":"Command Injection Vulnerability in find-exec","details":"Older versions of the package are vulnerable to Command Injection as an attacker controlled parameter. As a result, attackers may run malicious commands.\n\nFor example:\n\n```\nconst find = require(\"find-exec\");\nfind(\"mplayer; touch hacked\")\n```\n\nThis creates a file named \"hacked\" on the filesystem.\n\nYou should never allow users to control commands to find, since this package attempts to run every command provided.\n\nThanks to @miguelafmonteiro for reporting.","aliases":["CVE-2023-40582"],"modified":"2023-11-01T05:02:50.083551Z","published":"2023-08-30T20:08:58Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2023-08-30T20:08:58Z","nvd_published_at":"2023-08-30T18:15:09Z","cwe_ids":["CWE-78"]},"references":[{"type":"WEB","url":"https://github.com/shime/find-exec/security/advisories/GHSA-95rp-6gqp-6622"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-40582"},{"type":"WEB","url":"https://github.com/shime/find-exec/commit/74fb108097c229b03d6dba4cce81e36aa364b51c"},{"type":"PACKAGE","url":"https://github.com/shime/find-exec"}],"affected":[{"package":{"name":"find-exec","ecosystem":"npm","purl":"pkg:npm/find-exec"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.0.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/08/GHSA-95rp-6gqp-6622/GHSA-95rp-6gqp-6622.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}