← Back

Node Notifier

node-notifier

Vendor: Node Notifier Project • 1 CVE

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Node Notifier Project
1Node Notifier
Nov 21, 2024
Dec 11, 2020
N/A· v4
5.6 MEDIUM· v3
6.8 MEDIUM· v2
This affects the package node-notifier before 9.0.0. It allows an attacker to run arbitrary commands on Linux machines due to the options params not being sanitised when being passed an array.