CVE-2021-23378

Name
CVE-2021-23378
Description
This affects all versions of package picotts. If attacker-controlled user input is given to the say function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://snyk.io/vuln/SNYK-JS-PICOTTS-1078539
MISC https://github.com/luisivan/node-picotts/blob/8c6b183b884890c8e9422f93036b374942398c8b/index.js%23L16

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:picotts_project:picotts:*:*:*:*:*:node.js:*:* picotts == None == None

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
picotts edge-community 0.1_git20190912-r0 Celeste <cielesti@protonmail.com> possibly vulnerable
picotts 3.19-community 0.1_git20190912-r0 Celeste <cielesti@protonmail.com> possibly vulnerable