diskusage-ng@0.2.4 vulnerabilities

Get disk usage info in pure JS via OS built-in tools

Direct Vulnerabilities

Known vulnerabilities in the diskusage-ng package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Command Injection

diskusage-ng is a package that get disk usage info in pure JavaScript and without any dependencies.

Affected versions of this package are vulnerable to Command Injection. The argument path can be controlled by users without any sanitization.

How to fix Command Injection?

Upgrade diskusage-ng to version 1.0.0 or higher.

<1.0.0