← Back to CVE List

CVE-2020-26301

Published: 2021-09-20T20:15Z
Last Modified: 2024-11-21T05:19Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
ssh2 is client and server modules written in pure JavaScript for node.js. In ssh2 before version 1.4.0 there is a command injection vulnerability. The issue only exists on Windows. This issue may lead to remote code execution if a client of the library calls the vulnerable method with untrusted input. This is fixed in version 1.4.0. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt