用于从 npm 项目中生成 CycloneDX 软件物料清单(SBOM)。在 6.0.0 版本之前, 中的 Windows 回退路径(在 未能提供 npm CLI 路径时使用)可能会构造出包含来自 选项中不可信值的 shell 命令。当攻击者能够影响该选项值,且触发了回退的 npm 执行路径时,workspace 值中的 shell 元字符可能导致以运行 CLI 的用户权限执行任意操作系统命令,从而导致数据泄露、文件被修改或服务中断。该问题已在 6.0.0 版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| CycloneDX | cyclonedx-node-npm | < 6.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet