CVE-2018-16462: Apex-Publish-Static-Files Project Apex-Publish-Static-Files
Critical severity, CVSS 10.0. EPSS: 7% chance of exploitation in the next 30 days.
A command injection vulnerability in the apex-publish-static-files npm module version <2.0.1 which allows arbitrary shell command execution through a maliciously crafted argument.
Affected products
- Apex-Publish-Static-Files Project Apex-Publish-Static-Files: before 2.0.1 (fixed in 2.0.1)
Published 2018-10-30. Last modified 2026-06-17.