Hacker News new | ask | show | jobs
by micaksica 3605 days ago
I actually looked at the code for 5 minutes. This module is vulnerable to arbitrary code execution simply by having a malicious JavaScript file in a directory or subdirectory underneath where `auto-install` is run, without the user even needing to make a typo due to its design.

The documentation currently just says 'avoid typos'.

siddharthkp: please give me a way to contact you. see my contact info on my profile.

3 comments

>The documentation currently just says 'avoid typos'.

So their security model is basically the same as with C: "do it perfectly the first time."

DM on twitter? I'm @siddharthkp
Your DMs are closed.
Sorry about that, fixed.
They have an email address on their profile page.
Really? I don't see it.

https://news.ycombinator.com/user?id=siddharthkp doesn't return an email address, and I don't see one on the GitHub profile page either.

Thanks. Reaching out.