CVE-2020-26301

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
20/09/2021
Last modified:
01/10/2021

Description

ssh2 is client and server modules written in pure JavaScript for node.js. In ssh2 before version 1.4.0 there is a command injection vulnerability. The issue only exists on Windows. This issue may lead to remote code execution if a client of the library calls the vulnerable method with untrusted input. This is fixed in version 1.4.0.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ssh2_project:ssh2:*:*:*:*:*:node.js:*:* 1.4.0 (excluding)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*