Command Injection Affecting google-it package, versions *
Threat Intelligence
Exploit Maturity
Proof of concept
EPSS
1.94% (90th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JS-GOOGLEIT-2859196
- published 6 Jun 2022
- disclosed 3 Jun 2022
- credit Adar Zandberg
Introduced: 3 Jun 2022
CVE-2021-34083 Open this link in a new tabHow to fix?
There is no fixed version for google-it
.
Overview
google-it is an A CLI and Node.js library to help retrieve, display, and store Google search results
Affected versions of this package are vulnerable to Command Injection. When using the 'Open in browser' option, it will unsafely conver the result's link retrieved from google to a shell command.
PoC:
https://www.website.com/?a=`touch${IFS}HACKED`
References
CVSS Scores
version 3.1