CVE-2019-10061

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
26/03/2019
Last modified:
24/08/2020

Description

utils/find-opencv.js in node-opencv (aka OpenCV bindings for Node.js) prior to 6.1.0 is vulnerable to Command Injection. It does not validate user input allowing attackers to execute arbitrary commands.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:node-opencv_project:node-opencv:*:*:*:*:*:node.js:*:* 6.1.0 (excluding)