Junglewise Threat Intelligence

CVE-2019-5479: larvitbase-api unintended require vulnerability

CVE-2019-5479 · Severity: low · CVSS 3.1 · Published 2019-09-11

Vendors: npm.

Executive brief

larvitbase-api is a Node.js library that exposes API endpoints for web applications. A flaw in the library allows attackers to execute arbitrary JavaScript files on the server by manipulating an unsanitized GET parameter passed to a require() call, potentially leading to full server compromise.

Technical details

The vulnerability is an unsafe dynamic module loading issue (CWE-829) in larvitbase-api versions prior to 0.5.4. The package exposes an API endpoint that accepts a GET parameter and passes it directly to Node.js's require() function without sanitization. This allows an unauthenticated remote attacker to execute arbitrary .js files in the same directory as the server by crafting a malicious request. The attack requires only network access and can lead to remote code execution with the privileges of the running Node.js process. Fix: upgrade to version 0.5.4 or later.

Affected products

  • npm larvitbase-api prior to 0.5.4

Timeline

  • 2019-09-11: disclosed: Vulnerability published in GitHub Advisory Database
  • 2019-09-04: patched: Fix available in version 0.5.4 or later

References