Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-21129


Versions of the package nemo-appium before 0.0.9 are vulnerable to Command Injection due to improper input sanitization in the 'module.exports.setup' function. **Note:** In order to exploit this vulnerability appium-running 0.1.3 has to be installed as one of nemo-appium dependencies.


Published

2023-01-31T05:15:11.060

Last Modified

2025-03-27T18:15:19.120

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.4 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-78
  • Type: Primary
    NVD-CWE-Other
  • Type: Secondary
    CWE-77

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application paypal nemo-appium < 0.0.9 Yes

References