Junglewise Threat Intelligence

CVE-2022-25908: create-choo-electron command injection in devInstall

CVE-2022-25908 · Severity: low · CVSS 3.1 · Published 2023-01-26

Vendors: npm.

Executive brief

create-choo-electron is an npm package used to scaffold Electron applications with the Choo framework. A command injection vulnerability in the devInstall function allows attackers to execute arbitrary system commands by injecting shell metacharacters into user input, potentially leading to complete system compromise.

Technical details

The vulnerability is a command injection (CWE-78) in the devInstall function caused by improper sanitization of user-supplied input before passing it to system command execution. The attack vector is local with no special privileges required; attackers can inject shell metacharacters (e.g., "&") into function parameters to execute arbitrary commands. The vulnerability affects all versions of create-choo-electron through 2.0.0, and no patched version is currently available. An attacker who can invoke the devInstall function with untrusted input gains arbitrary code execution in the context of the process.

Affected products

  • create-choo-electron create-choo-electron all versions through 2.0.0

Timeline

  • 2022-12-06: disclosed
  • 2023-01-26: advisory

References