Executive brief
The freediskspace npm package is a utility library used by applications to check available disk space. A command injection flaw allows attackers to execute arbitrary system commands remotely without authentication by crafting malicious input. This could enable attackers to gain full control of systems running vulnerable applications, compromise data, and disrupt operations.
Technical details
This is a command injection vulnerability (CWE-78) in the freediskspace npm package affecting all versions up to 1.2.0. The flaw arises from improper neutralization of arguments at line 71 of freediskspace.js, where user-controlled input is passed unsanitized to a system command execution function. The attack vector is network-based with no authentication or user interaction required, and attack complexity is low. A remote attacker can inject shell metacharacters or command separators to execute arbitrary system commands in the context of the application. This results in complete compromise of confidentiality, integrity, and availability. No patched version is currently available.
Affected products
- npm freediskspace up to 1.2.0
Timeline
- 2020-11-17: disclosed
- 2021-02-02: advisory: NVD published
- 2021-04-13: advisory: GHSA published