Thanks for developing this great npm package! We find a potential command injection vulnerability from it.
The bug is introduced because package-exported method fails to sanitize the inputPw parameter and let it flow into a sensitive command execution API.
Hi,
Thanks for developing this great npm package! We find a potential command injection vulnerability from it. The bug is introduced because package-exported method fails to sanitize the
inputPw
parameter and let it flow into a sensitive command execution API.Here is the proof of concept.