Unitech / Unitech/pm2

Command Injection

Open
#4,491 7 comments 2 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
JavaScript
Stars
43.3k
Forks
2.7k
PR merge metrics
No merged PRs in 30d

Description

A command injection issue was openly disclosed on hackerone: https://hackerone.com/reports/633364

Has this already been fixed on newly released versions of pm2?

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing HackerOne report 633364 and comparing the reported command-injection behavior with current pm2 releases. Check whether the issue is fixed in released versions; if not, identify the affected command path and define a regression test that demonstrates the expected safe behavior.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript, node.js
Domain
cli, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.