Executive brief
ssh2 is a widely-used JavaScript library for implementing SSH client and server functionality in Node.js applications. A command injection vulnerability in versions before 1.4.0 allows remote code execution on Windows systems when an application passes untrusted input to certain library methods, potentially giving attackers full control over the affected server.
Technical details
The vulnerability is an OS command injection (CWE-78) in the ssh2 library affecting Windows systems only. The flaw exists in how the library handles shell command construction, allowing an attacker to inject arbitrary operating system commands through untrusted input passed to vulnerable library methods. The attack vector is network-based and does not require authentication or user interaction, though it does require the application to call the vulnerable method with attacker-controlled data. Successful exploitation results in remote code execution with the privileges of the process running the library. The vulnerability was fixed in version 1.4.0.
Affected products
- mscdex ssh2 before 1.4.0
Timeline
- 2021-09-21: disclosed
- 2021-09-21: patched: Fixed in version 1.4.0