Junglewise Threat Intelligence

CVE-2021-23356: kill-process-by-name code injection

CVE-2021-23356 · Severity: low · CVSS 3.1 · Published 2021-03-19

Vendors: npm.

Executive brief

kill-process-by-name is a Node.js package used to terminate running processes by name. An attacker can inject arbitrary shell commands through unsanitized user input, allowing them to execute any command with the privileges of the Node.js process. This could lead to full compromise of any application using this package if it processes untrusted input.

Technical details

The vulnerability is a code injection flaw (CWE-77) in the kill-process-by-name npm package caused by unsanitized use of the Node.js child_process.exec() function in index.js. If an attacker controls the process name parameter passed to the function, they can inject shell metacharacters to execute arbitrary commands. The attack requires the vulnerable application to accept and process untrusted input as a process name, but requires no authentication or user interaction. Exploitation grants the attacker command execution with the privileges of the Node.js process. No patched version has been released; the package remains vulnerable in all released versions.

Affected products

  • kill-process-by-name kill-process-by-name all versions up to 1.0.5

Timeline

  • 2021-02-23: disclosed
  • 2021-03-15: advisory
  • 2021-03-19: other: GHSA advisory published

References