CVE-2023-26143
Estado: ModificadaCrítica (9.1)—
Versions of the package blamer before 1.0.4 are vulnerable to Arbitrary Argument Injection via the blameByFile() API. The library does not sanitize for user input or validate the given file path conforms to a specific schema, nor does it properly pass command-line flags to the git binary using the double-dash POSIX characters (--) to communicate the end of options.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
- Puntuación base: 9.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.12%
- Percentil entre todas las CVEs puntuadas: 65
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-88
- CWE-88
Referencias
- https://gist.github.com/lirantal/14c3686370a86461f555d3f0703e02f9
- https://github.com/kucherenko/blamer/commit/0965877f115753371a2570f10a63c455d2b2cde3
- https://security.snyk.io/vuln/SNYK-JS-BLAMER-5731318
- https://gist.github.com/lirantal/14c3686370a86461f555d3f0703e02f9
- https://github.com/kucherenko/blamer/commit/0965877f115753371a2570f10a63c455d2b2cde3
- https://security.snyk.io/vuln/SNYK-JS-BLAMER-5731318
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-26143",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2023-26143",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-09-25T15:25:39.384737Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "report@snyk.io",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 2.5,
"exploitabilityScore": 3.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.1,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 5.2,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "report@snyk.io",
"affectedData": [
{
"vendor": "n/a",
"product": "blamer",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "1.0.4",
"versionType": "semver"
}
]
}
]
}
],
"published": "2023-09-19T05:17:10.443",
"references": [
{
"url": "https://gist.github.com/lirantal/14c3686370a86461f555d3f0703e02f9",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "report@snyk.io"
},
{
"url": "https://github.com/kucherenko/blamer/commit/0965877f115753371a2570f10a63c455d2b2cde3",
"tags": [
"Patch"
],
"source": "report@snyk.io"
},
{
"url": "https://security.snyk.io/vuln/SNYK-JS-BLAMER-5731318",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "report@snyk.io"
},
{
"url": "https://gist.github.com/lirantal/14c3686370a86461f555d3f0703e02f9",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/kucherenko/blamer/commit/0965877f115753371a2570f10a63c455d2b2cde3",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://security.snyk.io/vuln/SNYK-JS-BLAMER-5731318",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "report@snyk.io",
"description": [
{
"lang": "en",
"value": "CWE-88"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-88"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Versions of the package blamer before 1.0.4 are vulnerable to Arbitrary Argument Injection via the blameByFile() API. The library does not sanitize for user input or validate the given file path conforms to a specific schema, nor does it properly pass command-line flags to the git binary using the double-dash POSIX characters (--) to communicate the end of options."
},
{
"lang": "es",
"value": "Las versiones del paquete blamer anteriores a 1.0.4 son vulnerables a la inyección Arbitraria de Argumentos a través de la API blameByFile(). La librería no sanitiza la entrada del usuario ni valida que la ruta de archivo dada se ajuste a un esquema específico, ni pasa correctamente los indicadores de línea de comandos al binario git utilizando los caracteres POSIX de doble guión (--) para comunicar el final de las opciones. "
}
],
"lastModified": "2026-06-17T05:42:46.447",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:blamer_project:blamer:*:*:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "A8E6FC04-030F-4B2D-9484-213E324BBB7A",
"versionEndExcluding": "1.0.4"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "report@snyk.io"
}