react-dev-utils OS Command Injection in function `getProcessForPort`
Moderate severity
GitHub Reviewed
Published
Mar 11, 2021
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Mar 9, 2021
Reviewed
Mar 11, 2021
Published to the GitHub Advisory Database
Mar 11, 2021
Last updated
Jan 27, 2023
react-dev-utils prior to v11.0.4 exposes a function,
getProcessForPort
, where an input argument is concatenated into a command string to be executed. This function is typically used from react-scripts (in Create React App projects), where the usage is safe. Only when this function is manually invoked with user-provided values (ie: by custom code) is there the potential for command injection. If you're consuming it from react-scripts then this issue does not affect you.References