FixVibe

high

OS Command Injection in install-package (CVE-2020-7629)

install-package 0.4.0 and earlier is affected by CVE-2020-7629, an OS command injection. FixVibe GitHub repo scans flag affected install-package versions in npm manifests and lockfiles.

CVE-2020-7629GHSA-6m4r-m3gc-h4r5CWE-78

Public advisories list install-package 0.4.0 and earlier as affected by CVE-2020-7629 / GHSA-6m4r-m3gc-h4r5. The package can be used in Node services, admin automation, CI, and developer tooling, so the useful security question is whether a repository still installs an affected release where untrusted package-install input could matter.

Impact

Affected install-package versions can expose OS command-injection risk when attacker-controlled package-install options reach the vulnerable helper. A dependency match is important patch-triage evidence for Node runtimes, automation, CI, and developer hosts, but it is not the same as proving that a production web app is exploitable.

Covered by FixVibe

FixVibe's GitHub repo scans flag npm manifests or lockfiles that resolve install-package to 0.4.0 or earlier, showing the package, file, line, version and advisory IDs so you can prioritize cleanup.

Remediation

GitHub's reviewed advisory and NVD list 0.4.0 and earlier as affected, while Snyk and current npm metadata indicate 0.4.1 or newer is available. Upgrade install-package to 0.4.1 or newer where the package is intentionally retained, or remove/replace it with maintained package-install tooling.

Regenerate the active npm, pnpm, or Yarn lockfile, rebuild runtime images, worker images, devcontainers, package-manager caches, and CI artifacts that install dependencies, and review call sites so untrusted package names or install options cannot reach package-install helpers. After cleanup, rerun the FixVibe GitHub repo scan to confirm the affected dependency evidence is gone.