Executive brief
killport is a utility that terminates processes listening on a specified network port. A command injection vulnerability allows an attacker to execute arbitrary system commands by providing a malicious port number, potentially compromising the system running the tool and enabling unauthorized code execution.
Technical details
This is a command injection vulnerability (CWE-77) in the killport npm package. The vulnerable code uses Node.js child_process.exec() to run an lsof command with an unsanitized user-supplied port parameter, allowing an attacker to inject shell metacharacters and execute arbitrary commands. The vulnerability requires local access or the ability to supply input to the killport function; an attacker can craft a malicious port string (e.g., containing shell operators like `;` or `|`) to break out of the intended lsof command. The fix, released in version 1.0.2, adds input validation using a regular expression to ensure the port parameter contains only digits before passing it to exec().
Affected products
- killport killport before 1.0.2
Timeline
- 2021-04-13: disclosed: GitHub Security Advisory published
- 2021: patched: Fixed in version 1.0.2