EXPOSURES › CVE-2021-21315
CVE-2021-21315
HIGH ⌖ ON CISA KEV · EXPLOITEDA Node.js package allowed remote command execution via a malicious payload in the name parameter.
The System Information Library for Node.js suffered a command injection flaw enabling remote code execution, which is now on CISA's KEV list. DIB organizations must audit third-party npm packages for unpatched RCE vulnerabilities to prevent supply-chain compromises and ensure compliance with NIST 800-171's supply-chain security requirements.
Shame score — A known command injection vulnerability was left unpatched long enough to be added to CISA's KEV list, indicating negligent maintenance and avoidable exposure to remote code execution.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
In this vulnerability, an attacker can send a malicious payload that will exploit the name parameter. After successful exploitation, attackers can execute remote.