CVE-2020-28429: GEOJSON2KML Project GEOJSON2KML

Critical severity, CVSS 9.8. EPSS: 63.3% chance of exploitation in the next 30 days.

All versions of package geojson2kml are vulnerable to Command Injection via the index.js file. PoC: var a =require("geojson2kml"); a("./","& touch JHU",function(){})

Affected products

Published 2021-02-23. Last modified 2026-06-17.