CVE-2020-28429: GEOJSON2KML Project GEOJSON2KML
Critical severity, CVSS 9.8. EPSS: 63.3% chance of exploitation in the next 30 days.
All versions of package geojson2kml are vulnerable to Command Injection via the index.js file. PoC: var a =require("geojson2kml"); a("./","& touch JHU",function(){})
Affected products
- GEOJSON2KML Project GEOJSON2KML: any version
Published 2021-02-23. Last modified 2026-06-17.