Cowsay As A Service
Prototype pollution leads to RCE
Description
Solution
router.get('/cowsay', (ctx, next) => {
const setting = settings[ctx.state.user];
const color = setting?.color || '#000000';
let cowsay = '';
if (ctx.request.query.say) {
const result = child_process.spawnSync('/usr/games/cowsay', [ctx.request.query.say], { timeout: 500 });
cowsay = result.stdout.toString();
}
Last updated