node-opencv was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-506,CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| node-opencv_project | node-opencv | * |
utils/find-opencv.js in node-opencv (aka OpenCV bindings for Node.js) prior to 6.1.0 is vulnerable to Command Injection. It does not validate user input allowing attackers to execute arbitrary commands.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| node-opencv_project | node-opencv | * |