
OS Command Injection (CVE-2020-7629) in `install-package` allows for arbitrary command execution. Investigate your environments for this `npm` package. #OSCommandInjection #CVE #InfoSec https://www.pulsepatch.io/posts/cve-2020-7629-install-package-os-command-injection
Post summary
The post announces the OS Command Injection flaw (CVE‑2020‑7629) in the npm install-package package, detailing the risk of arbitrary command execution.
