advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXhoangtbWZyNi05cnI0

Command Injection in samsung-remote

Versions of samsung-remote before 1.3.5 are vulnerable to command injection. This vulnerability is exploitable if user input is passed into the ip option of the package constructor.

Recommendation

Update to version 1.3.5 or later.

Permalink: https://github.com/advisories/GHSA-xhjx-mfr6-9rr4
JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXhoangtbWZyNi05cnI0
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Critical
Classification: General
Published: over 4 years ago
Updated: about 2 years ago


Identifiers: GHSA-xhjx-mfr6-9rr4
References: Blast Radius: 0.0

Affected Packages

npm:samsung-remote
Dependent packages: 21
Dependent repositories: 29
Downloads: 650 last month
Affected Version Ranges: < 1.3.5
Fixed in: 1.3.5
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.1.0, 1.2.0, 1.2.1, 1.2.2, 1.2.3, 1.2.4, 1.2.5
All unaffected versions: 1.3.5, 1.3.6, 1.4.0, 1.4.1, 1.4.2, 1.5.0, 1.5.1, 1.5.2, 1.6.0, 1.6.2, 2.0.0, 2.0.1