mbox-to-json is vulnerable to Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
60
Medium Risk
Affected versions of this package are vulnerable to Command Injection via Unsafe Subprocess Execution where the attachment extraction feature directly concatenates user-controlled filenames into a shell command without sanitization, enabling attackers to exploit this by crafting malicious filenames containing shell metacharacters (e.g., semicolons or backticks) to execute arbitrary commands on the system, potentially leading to unauthorized access, data theft, or full compromise.
You are affected if you are using a vulnerable version of the package.
mbox-to-json is vulnerable to Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in versions 1.0.0 - 1.0.5.
Upgrade the mbox-to-json library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant