{"id":"GHSA-cr6m-62pq-hmqh","summary":"OS Command injection in npm-lockfile","details":"npm-lockfile safely generates an npm lockfile and output it to the filename of your choice. npm-lockfile before 2.0.4 does not santize unsafe external input and invoke sensitive command execution API with the input, causing command injection vulnerability. A fix was released in version 2.0.5.","aliases":["CVE-2022-0841"],"modified":"2023-11-01T04:57:13.634648Z","published":"2022-03-04T00:00:18Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2022-03-04T21:20:11Z","nvd_published_at":"2022-03-03T16:15:00Z","cwe_ids":["CWE-78"],"severity":"CRITICAL"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-0841"},{"type":"WEB","url":"https://github.com/ljharb/npm-lockfile/commit/bfdb84813260f0edbf759f2fde1e8c816c1478b8"},{"type":"PACKAGE","url":"https://github.com/ljharb/npm-lockfile"},{"type":"WEB","url":"https://huntr.dev/bounties/4f806dc9-2ecd-4e79-997e-5292f1bea9f1"}],"affected":[{"package":{"name":"npm-lockfile","ecosystem":"npm","purl":"pkg:npm/npm-lockfile"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.0.3"},{"fixed":"2.0.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-cr6m-62pq-hmqh/GHSA-cr6m-62pq-hmqh.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}