Horizon Alert
Summary of the vulnerability and why it matters
This advisory addresses a vulnerability in a Node.js library that could allow attackers to execute commands on the server if the library is used in a way that processes unsanitized user input. The primary concern is to confirm if this library is in use and if it is exposed to external input.
- Unsanitized input can execute server commands.
- Understand if this library is part of our systems.
- Confirm if it's exposed to external input.
Attack Path
How an attacker could exploit the issue
An attacker can exploit this vulnerability by sending specially crafted input, likely through a web application that uses the affected library. This input, containing malicious shell metacharacters, is passed to a function that executes system commands without proper sanitization. Successful exploitation allows an attacker to run arbitrary operating system commands with the privileges of the Node.js process.
- Entry condition: Network access to an application using the library.
- Trigger point: Unsanitized filepath and convertTo arguments.
- Resulting risk: Arbitrary OS command execution.
Live Threat
Current exploitation, exposure, and threat context
The `@enmaso/node-convert` library, when used with versions up to 1.0.0, allows for the execution of arbitrary operating system commands. This is possible because unsanitized input in the `filepath` and `convertTo` arguments can be used to inject malicious commands into the ImageMagick process. When this vulnerability is exploited, an attacker could potentially execute commands with the same privileges as the Node.js process.
- System data and behavior.
- Via unsanitized input to arguments.
- Arbitrary command execution.
Operational Fix
Recommended remediation, mitigation, and detection steps
The `@enmaso/node-convert` library's OS command injection vulnerability in `convert.js` impacts Node.js applications. Owners of applications that utilize this library, particularly those processing user-supplied file paths or conversion targets, are responsible for assessing and mitigating risk. The first practical step is to identify all instances of the affected library, determine their reachability and business criticality, and then plan remediation.
- Application owners should manage this issue.
- Verify library usage and exposure paths.
- Plan coordinated remediation and testing.