CVE-2024-21488 is a critical arbitrary command injection vulnerability affecting versions of the 'network' package for Node.js prior to 0.7.0. It arises from unsanitized user input being passed to the 'mac_address_for' function, allowing attackers to execute arbitrary commands on the host operating system. With a CVSS score of 9.8 (Critical), this vulnerability is easily exploitable over the network with no user interaction, leading to complete compromise of confidentiality, integrity, and availability. While no public exploit code or active exploitation has been confirmed, it has garnered some community discussion, indicating awareness of its severity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.7.0CPE matchmatch criteria | cpe:2.3:a:forkhq:network:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.