We found results for “


Date: September 25, 2019

Cocos-utils is vulnerable in all version to Remote Code Execution. The unzip() function concatenates user input to exec() this can lead attackers to execute arbitrary commands on the server.

Language: JS

Severity Score

Severity Score

Weakness Type (CWE)



CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): LOW
User Interaction (UI): NONE
Scope (S): CHANGED
Confidentiality (C): HIGH
Integrity (I): HIGH
Availability (A): HIGH

Do you need more information?

Contact Us