Junglewise Threat Intelligence

CVE-2021-23355: ps-kill command injection vulnerability

CVE-2021-23355 · Severity: low · CVSS 3.1 · Published 2021-03-19

Vendors: npm.

Executive brief

ps-kill is a Node.js library used to terminate running processes on a system. The library fails to sanitize user input passed to its kill function, allowing an attacker to inject and execute arbitrary shell commands with the privileges of the application using the library. This could lead to unauthorized code execution, data theft, or system compromise depending on how the library is deployed.

Technical details

The vulnerability is a command injection flaw (CWE-77) in the ps-kill npm package affecting all versions up to and including 1.0.0. The root cause is unsafe use of Node.js child_process.exec() without input sanitization in the index.js file. When attacker-controlled input is passed to the kill() function, shell metacharacters (such as command substitution syntax like $(command)) are not escaped, allowing arbitrary command execution. No authentication is required—the vulnerability is triggered simply by calling the function with malicious input. The proof-of-concept demonstrates execution of arbitrary commands like touch success. There is no patched version available for this library.

Affected products

  • npm ps-kill all versions up to 1.0.0

Timeline

  • 2021-02-23: disclosed
  • 2021-03-15: advisory
  • 2021-03-19: other: Published to GitHub advisory database

References