The @ronomon/opened library before 1.5.2 is vulnerable to a command injection vulnerability which would allow a remote attacker to execute commands on the system if the library was used with untrusted input.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| @ronomon/opened(npm) | 0 | 1.5.2 | N/A |
CVSS Metrics