Command Injection in forsigner/node-pngdefry

Valid

Reported on

May 8th 2020


Overview

Affected versions execute arbitrary commands remotely inside the victim's PC. The issue occurs because user input is formatted inside a command that will be executed without any checks.

Occurrences

References

to join this conversation