CVE-2018-16460
Published Sep 7, 2018A command Injection in ps package versions <1.0.0 for Node.js allowed arbitrary commands to be executed when attacker controls the PID.
Vendor archive
2 CVEs tagged to vendor umbraengineering — 2 Critical, 0 High, 0 Medium, 0 Low, 0 Unrated.
A command Injection in ps package versions <1.0.0 for Node.js allowed arbitrary commands to be executed when attacker controls the PID.
The utilities function in all versions <= 0.3.0 of the merge-recursive node module can be tricked into modifying the prototype of Object when the attacker can control part of the…