Aller au contenu

Fiche vulnérabilité

CVE-2022-21191 : faille critique global-modules-path project… (CVSS 9.8)

Description

Versions of the package global-modules-path before 3.0.0 are vulnerable to Command Injection due to missing input sanitization or other checks and sandboxes being employed to the getPath function.

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
13 janv. 2023
Dernière mise à jour
17 juin 2026

Produits concernés

  • global-modules-path project global-modules-path

Références

Rechercher une autre vulnérabilité dans la base CVE