Junglewise Threat Intelligence

CVE-2021-21412: thi.ng egf OS command injection via GPG tag decryption

CVE-2021-21412 · Severity: low · CVSS 3.1 · Published 2021-04-06

Vendors: npm.

Executive brief

The thi.ng/egf library is a data format parser used in Node.js applications. When the GPG decryption feature is enabled, it fails to properly validate encrypted property values, allowing an attacker to inject arbitrary operating system commands through specially crafted backtick characters. This could lead to unauthorized code execution on servers processing untrusted EGF files.

Technical details

The vulnerability is an OS command injection (CWE-78) in the `#gpg`-tagged property value handling when decryption is enabled. The root cause is improper neutralization of backtick (`) characters in encrypted values, which are interpreted as shell command substitution by the underlying GPG decryption logic. An attacker must supply a malicious EGF file with a `#gpg`-tagged value containing backticks and the application must have the `decrypt: true` option enabled. No authentication is required; network reachability depends on how the application accepts EGF input. Successful exploitation allows arbitrary command execution with the privileges of the Node.js process. The fix was released in version 0.4.0 (2021-03-27).

Affected products

  • thi.ng egf <0.4.0

Timeline

  • 2021-03-30: disclosed
  • 2021-03-27: patched: v0.4.0

References