Executive brief
window-control is an npm package used to manage window focus in Node.js applications. Versions before 1.4.5 contain a command injection vulnerability in the sendKeys function due to improper sanitization of user input, allowing an attacker to execute arbitrary system commands on the affected system.
Technical details
window-control is vulnerable to command injection (CWE-77) in the sendKeys function due to improper input sanitization. An attacker with local access and the ability to call the sendKeys function with unsanitized input can inject arbitrary shell commands that will be executed by the application. The vulnerability requires the attacker to have local access and sufficient privileges to invoke the vulnerable function. The fix, released in version 1.4.5, adds proper input sanitization to prevent command injection attacks. Patches are available and users should upgrade to version 1.4.5 or later.
Affected products
- window-control window-control before 1.4.5
Timeline
- 2023-01-04: disclosed
- 2023-01-04: patched: Fixed in version 1.4.5