CVE-2018-13797: Node-Macaddress Project Node-Macaddress
Critical severity, CVSS 9.8. EPSS: 6.7% chance of exploitation in the next 30 days.
The macaddress module before 0.2.9 for Node.js is prone to an arbitrary command injection flaw, due to allowing unsanitized input to an exec (rather than execFile) call.
Affected products
- Node-Macaddress Project Node-Macaddress: before 0.2.9 (fixed in 0.2.9)
Published 2018-07-10. Last modified 2026-06-17.