Dnt develops image processing and metadata handling utilities, with observed vulnerabilities centered on OS command-injection flaws in its metadata and image-resizing components. These disclosures reflect input-handling risks common to tools that invoke system commands to manipulate media files; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dnt over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-10787CRITICAL im-resize through 2.3.2 allows remote attackers to execute arbitrary commands via the "exec" argument. The cmd argument used within index.js, can be controlled by user without any | Feb 4, 2020 | 9.8 | 30 | NO | NO |
CVE-2019-10788CRITICAL im-metadata through 3.0.1 allows remote attackers to execute arbitrary commands via the "exec" argument. It is possible to inject arbitrary commands as part of the metadata options | Feb 4, 2020 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dnt.
Media articles that mention a CVE ID that affects a product developed by Dnt — matched by CVE ID, not by vendor name.