Skip to content

[GHSA-28xh-wpgr-7fm8] Command Injection in open#7450

Open
Wenxin-Jiang wants to merge 1 commit intoWenxin-Jiang/advisory-improvement-7450from
Wenxin-Jiang-GHSA-28xh-wpgr-7fm8
Open

[GHSA-28xh-wpgr-7fm8] Command Injection in open#7450
Wenxin-Jiang wants to merge 1 commit intoWenxin-Jiang/advisory-improvement-7450from
Wenxin-Jiang-GHSA-28xh-wpgr-7fm8

Conversation

@Wenxin-Jiang
Copy link
Copy Markdown

Updates

  • Affected products

Comments

  • open@0.0.0 (270-byte tarball, 295-byte package.json): contains only package/package.json — no lib/, no vendor/, no JS at all. Pure stub. shasum: 7b5f1e7b, published 2012-04-14.
  • open@0.0.2 (first real release — 0.0.1 does not exist on npm): contains lib/open.js with both the vulnerable escape() function and the exec(opener + ' "' + escape(target) + '"', callback)
    command-execution sink.
  • The vulnerable code path is demonstrably absent from 0.0.0 and first introduced in 0.0.2.

@github-actions github-actions bot changed the base branch from main to Wenxin-Jiang/advisory-improvement-7450 April 20, 2026 14:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant