-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from the setup function in index.js handling the 'apath' parameter. The commit diff shows added validation for 'apath' ending with 'appium' and prohibiting spaces, directly addressing command injection. The test case modification demonstrates exploitability via command chaining ('touch HACKED'). The CWE mapping and advisory descriptions confirm this is an OS command injection via improper input sanitization in this function.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| nemo-appium | npm | < 0.0.9 | 0.0.9 |
Ongoing coverage of React2Shell