Junglewise Threat Intelligence

CVE-2023-40582: find-exec command injection vulnerability

CVE-2023-40582 · Severity: low · CVSS 3.1 · Published 2023-08-30

Vendors: npm.

Executive brief

find-exec is a Node.js library that executes system commands based on user-provided input. The vulnerability allows attackers to inject arbitrary shell commands through unsanitized parameters, potentially leading to unauthorized command execution on affected systems. This could result in data theft, system compromise, or service disruption if the application using find-exec processes untrusted user input.

Technical details

The vulnerability is a command injection flaw (CWE-78) in find-exec versions prior to 1.0.3 that arises from insufficient input validation. The package directly passes user-controlled parameters to shell command execution without proper escaping or sanitization. An attacker can inject shell metacharacters (such as semicolons) to chain arbitrary commands; for example, calling find("mplayer; touch hacked") results in execution of both the intended command and the injected touch command. The attack requires only that an application using find-exec processes attacker-controlled input, with no authentication or special privileges required. The vulnerability is fixed in version 1.0.3 and later.

Affected products

  • find-exec find-exec <1.0.3

Timeline

  • 2023-08-30: disclosed
  • 2023-08-30: patched: Fixed in version 1.0.3

References