Quobject develops a Node.js wrapper library for the Docker command-line interface, providing programmatic access to Docker operations within JavaScript applications. The vendor's observed vulnerability signal centers on OS command-injection risks arising from the library's interaction with shell command construction, a structural concern in tools that bridge scripting languages to system-level operations. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Quobject over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-23732CRITICAL This affects all versions of package docker-cli-js. If the command parameter of the Docker.command method can at least be partially controlled by a user, they will be in a position | Nov 22, 2021 | 9.0 | 28 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Quobject.
Media articles that mention a CVE ID that affects a product developed by Quobject — matched by CVE ID, not by vendor name.