@enmaso/node-convert 1.0.0 及之前版本存在 OS 命令注入漏洞。该漏洞位于 convert.js 文件中,攻击者可以通过未经 sanitization(清理/过滤)的 filepath 和 convertTo 参数执行 Shell 命令。攻击者可以向由 child_process.exec() 调用的 ImageMagick 命令中注入 Shell 元字符或单引号,从而以 Node.js 进程的权限执行操作系统命令。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| enmaso | @enmaso/node-convert | ≤ 1.0.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| enmaso | @enmaso/node-convert | 0 ~ 1.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet