If an attacker can control the port, which in itself is a very sensitive value, they can inject arbitrary OS commands due to the usage of the exec function in a third-party module kill-port < 1.3.2.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| kill-port(npm) | 0 | 1.3.2 | N/A |
CVSS Metrics