CVE-2019-10783 is a critical command injection vulnerability affecting all versions of the lsof npm module, where every exported method improperly processes user input via the exec function. With a CVSS score of 9.8, this flaw allows unauthenticated remote attackers to execute arbitrary commands, leading to complete compromise of confidentiality, integrity, and availability. While the EPSS score is low and there's no evidence of active exploitation or public exploit code, the high FAUCET Risk Score of 83/100 indicates significant potential danger. There is no community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.0.4CPE matchmatch criteria | cpe:2.3:a:isof_project:isof:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.