Junglewise Threat Intelligence

CVE-2025-55294: screenshot-desktop command injection in format option

CVE-2025-55294 · Severity: low · CVSS 3.1 · Published 2025-08-19

Vendors: npm.

Executive brief

screenshot-desktop is a Node.js library that captures screenshots from applications. When user-supplied input is passed to the format option without validation, an attacker can inject arbitrary shell commands that execute with the application's privileges. In server-side contexts like web APIs, this allows unauthenticated remote attackers to run malicious commands on the hosting server, potentially leading to complete system compromise.

Technical details

This is an OS command injection vulnerability (CWE-77) in the screenshot function's format option. User-controlled input passed to the format parameter is directly interpolated into a shell command without sanitization or escaping. The vulnerability requires no authentication or user interaction and is network-exploitable when the library is used in server-side contexts. An attacker can craft payloads like `"; echo vulnerable > /tmp/hello;"` to execute arbitrary commands with the process's privileges. The issue was patched in version 1.15.2; all earlier versions remain vulnerable.

Affected products

  • bencevans screenshot-desktop <1.15.2

Timeline

  • 2025-08-19: disclosed
  • 2025-08-19: patched: Fixed in version 1.15.2

References