« Volver al listado

CVE-2020-7602

Estado: ModificadaCrítica (9.8)—💥 PoC

node-prompt-here through 1.0.1 allows execution of arbitrary commands. The "runCommand()" is called by "getDevices()" function in file "linux/manager.js", which is required by the "index. process.env.NM_CLI" in the file "linux/manager.js". This function is used to construct the argument of function "execSync()", which can be controlled by users without any sanitization.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

💥 Exploits públicos

Hay código de explotación o plantillas de detección públicos. No es lo mismo que explotación activa confirmada (KEV), pero aumenta el riesgo: parchee con prioridad.

⚠️ Las pruebas de concepto de GitHub no están verificadas: algunas son falsas o contienen malware. No las ejecute nunca fuera de un laboratorio aislado.

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-7602",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "report@snyk.io",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "node-prompt-here",
          "versions": [
            {
              "status": "affected",
              "version": "All versions including 1.0.1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-03-15T22:15:14.583",
  "references": [
    {
      "url": "https://snyk.io/vuln/SNYK-JS-NODEPROMPTHERE-560115",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "report@snyk.io"
    },
    {
      "url": "https://snyk.io/vuln/SNYK-JS-NODEPROMPTHERE-560115",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-78"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "node-prompt-here through 1.0.1 allows execution of arbitrary commands. The \"runCommand()\" is called by \"getDevices()\" function in file \"linux/manager.js\", which is required by the \"index. process.env.NM_CLI\" in the file \"linux/manager.js\". This function is used to construct the argument of function \"execSync()\", which can be controlled by users without any sanitization."
    },
    {
      "lang": "es",
      "value": "node-prompt-here versiones hasta 1.0.1, permite una ejecución de comandos arbitraria. La función \"runCommand()\" es llamada por una función \"getDevices()\" en el archivo \"linux/manager.js\", que es requerida por el \"index. process.env.NM_CLI\" en el archivo \"linux/manager.js\". Esta función es usada para construir el argumento de la función \"execSync()\", que puede ser controlada por los usuarios sin ningún tipo de saneamiento."
    }
  ],
  "lastModified": "2026-06-17T03:25:06.190",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:node-prompt-here_project:node-prompt-here:*:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8CEE4CEE-7B8B-4466-BC01-F0146980824E",
              "versionEndIncluding": "1.0.1"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "report@snyk.io"
}