CVE-2017-16042: Growl Project Growl

Critical severity, CVSS 9.8. EPSS: 4.4% chance of exploitation in the next 30 days.

Growl adds growl notification support to nodejs. Growl before 1.10.2 does not properly sanitize input before passing it to exec, allowing for arbitrary command execution.

Affected products

Published 2018-06-04. Last modified 2026-06-17.