Executive brief
monorepo-build is a Node.js build utility package used by developers to compile and manage monorepo projects. A command injection flaw in this package allows attackers to execute arbitrary operating system commands on a developer's machine or build server by passing malicious input to the build function. This could lead to complete system compromise, theft of source code and credentials, or deployment of malicious artifacts.
Technical details
The monorepo-build package contains a command injection vulnerability (CWE-77/CWE-78) in its build function, which fails to properly sanitize user-supplied input before passing it to shell execution. An attacker can inject shell metacharacters (such as `&` or `;`) into the build parameters to execute arbitrary commands with the privileges of the user running the build process. The vulnerability is network-reachable if the package is used in a context that processes untrusted input (e.g., CI/CD pipelines processing external requests), and no special privileges or user interaction is required. A proof-of-concept demonstrates command injection via `a.build("./","& touch 1111"," & touch shaaaa")`. There is no patched version available for this package; affected users should consider using alternative build tools.
Affected products
- monorepo-build monorepo-build all versions up to 0.1.9
Timeline
- 2020-12-11: disclosed
- 2022-08-03: advisory
- kev added: Referenced as CVE-2020-28423