
Vulnerabilities
Organisations Risk Remote Code Execution via Critical Command Injection in @enmaso/node-convert Library
A critical command injection flaw in @enmaso/node-convert allows remote execution of system commands through unsanitized inputs.
Everything Malware Brief has reported about OS command injection: 2 stories, newest first. Part of our Vulnerabilities coverage.

A critical command injection flaw in @enmaso/node-convert allows remote execution of system commands through unsanitized inputs.

A critical unauthenticated command injection in Dromara Skyeye allows remote attackers to execute PowerShell code on Windows servers via a text-to-speech endpoint.