Tag
#OS Command Injection
Critical Vulnerability in better-npm-audit: OS Command Injection via Registry Flag
A critical vulnerability, CVE-2026-57998, with a CVSS score of 7.8, was discovered in better-npm-audit, a popular npm package. The vulnerability allows for OS command injection via the --registry option, enabling attackers to execute arbitrary operating system commands with the privileges of the process running the audit. The vulnerability affects versions up to 3.11.0 and the 4.0.0-rc.2 prerelease. Immediate patching or mitigation is recommended to prevent potential exploitation.
Understanding and Defending Against OS Command Injection in systeminformation's networkInterfaces()
This educational analysis delves into a critical vulnerability in the systeminformation library, specifically in the networkInterfaces() function on Linux systems. The vulnerability allows for OS command injection through the Debian/Ubuntu interfaces(5) source directive, enabling an attacker to execute arbitrary commands with the privileges of the calling Node.js process. We will explore the root cause, attack surface, exploitation mechanics, and provide defensive strategies to mitigate this threat.
Dell Container Storage Modules OS Command Injection Vulnerability
A high-severity vulnerability (CVE-2026-40711, CVSS score of 8) exists in Dell Container Storage Modules, allowing a high-privileged attacker with remote access to potentially exploit the vulnerability, leading to command execution. Affected versions include csi-powerstore v2.16.0, csi-unity v2.16.0, csi-powerflex v2.16.0, and csi-powermax v2.16.0. Users should update to version 2.15.2 or later, or 2.17.0 or later.