Executive brief
This advisory has been withdrawn. The npm package "effect" (a Node.js image effect library) was claimed to have a command injection vulnerability, but the advisory was withdrawn because the npm package does not match the vulnerable GitHub repository, and the CVE issuer has since stated this was not actually a vulnerability.
Technical details
The original advisory alleged that the "effect" npm package through version 1.0.4 was vulnerable to OS command injection (CWE-78) via unsanitized user input in the options parameter. However, the advisory was withdrawn on June 4, 2024, for two critical reasons: (1) the npm package "effect" does not correspond to the vulnerable GitHub repository (https://github.com/Javascipt/effect), which is not in a supported ecosystem, and (2) the CVE Numbering Authority that issued CVE-2020-7624 has updated their advisory stating that "This was deemed not a vulnerability." As such, this is not an actionable security issue.
Affected products
- npm effect <= 1.0.4
Timeline
- 2020-04-02: disclosed
- 2022-02-10: advisory: Added to GitHub Advisory Database
- 2024-06-04: other: Advisory withdrawn; CVE issuer deemed not a vulnerability