Junglewise Threat Intelligence

CVE-2020-7614: npm-programmatic command injection

CVE-2020-7614 · Severity: low · CVSS 3.1 · Published 2020-04-23

Vendors: npm.

Executive brief

npm-programmatic is a Node.js library that allows JavaScript developers to programmatically run npm package management commands. The library contains a command injection flaw that allows attackers to execute arbitrary system commands if they can control the package names or options passed to the install, uninstall, or list functions. This could lead to full system compromise if the library processes untrusted input (e.g., from user uploads or API requests).

Technical details

The vulnerability is a classic command injection flaw (CWE-78) in which package names and user-supplied options are concatenated directly into shell command strings without sanitization before being passed to child_process.exec(). The vulnerable code is in the install(), uninstall(), and list() functions, where inputs such as package names, --cwd, and --save flags are joined into a string like "npm install [PACKAGES] [OPTIONS]" and executed as shell commands. An attacker can inject shell metacharacters (e.g., '&', '|', ';', backticks) into the package name to break out of the npm context and execute arbitrary code with the privileges of the Node process. Exploitation requires only the ability to control the input passed to one of these functions; no authentication or user interaction is needed. As of the advisory date, no patched version exists; users are advised to avoid the library or implement strict input validation if continued use is necessary.

Affected products

  • npm npm-programmatic 0 to 0.0.12 (all released versions)

Timeline

  • 2020-04-07: disclosed: Vulnerability initially disclosed
  • 2020-04-23: advisory: GHSA-426h-24vj-qwxf published
  • 2020-04-23: other: CVE-2020-7614 assigned

References