serial-number through 1.3.0 allows execution of arbritary commands. The "cmdPrefix" argument in serialNumber function is used by the "exec" function without any validation.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| serial-number(npm) | 0 | N/A | N/A |
CVSS Metrics