CVE-2018-3786: Eggjs Egg-Scripts

Critical severity, CVSS 9.8. EPSS: 12.3% chance of exploitation in the next 30 days.

A command injection vulnerability in egg-scripts <v2.8.1 allows arbitrary shell command execution through a maliciously crafted command line argument.

Affected products

  • Eggjs Egg-Scripts: before 2.8.1 (fixed in 2.8.1)

Published 2018-08-24. Last modified 2026-06-17.