Remote Code Execution (RCE) Affecting @vue/cli package, versions <4.5.14 >=5.0.0-alpha.0 <5.0.0-beta.6
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JS-VUECLI-1731684
- published 29 Nov 2021
- disclosed 14 Oct 2021
- credit Haoqun Jiang
How to fix?
Upgrade @vue/cli
to version 4.5.14, 5.0.0-beta.6 or higher.
Overview
@vue/cli is a Command line interface for rapid Vue.js development
Affected versions of this package are vulnerable to Remote Code Execution (RCE) on the user’s machine via Cross-Site WebSocket Hijacking.
Note: This vulnerability is exploitable only if the user explicitly exposes their Vue CLI UI server to the public network via the command vue ui -H 0.0.0.0
.
References
CVSS Scores
version 3.1