FixVibe

critical

OS Command Injection in jscover (CVE-2020-7623)

jscover through 1.0.0 is affected by CVE-2020-7623 command injection. FixVibe GitHub repo scans flag affected jscover versions in npm manifests and lockfiles.

CVE-2020-7623GHSA-c5hm-xc74-pqrgGHSA-c5hm-xc74-pqrgCWE-78

The jscover npm package through 1.0.0 is affected by CVE-2020-7623 / GHSA-c5hm-xc74-pqrg. Public advisories describe OS command injection risk in the JSCover wrapper when unsafe coverage source input reaches shell command construction [S1][S2].

Impact

If an application, CI job, build worker, or developer automation host runs the affected coverage wrapper with attacker-controlled source or target path input, the host running the coverage task could execute unintended operating-system commands. The practical impact depends on where jscover is installed, whether it is still invoked, and whether untrusted request, job, repository, or file-path data can reach the coverage command boundary [S1][S3].

Root Cause

jscover is a legacy npm wrapper around JSCover. The affected package builds an operating-system command from coverage arguments before invoking a child process, so unsafe source path input can cross into a shell-command context [S1][S4]. Public advisory metadata lists npm jscover through 1.0.0 as affected, with no patched version available [S1][S2].

FixVibe coverage

FixVibe's GitHub repo scans flag npm manifests and lockfiles that resolve jscover in the affected range, with the package, source file, version and advisory references [S1][S2].

Remediation

Remove jscover or replace it with maintained coverage tooling such as c8, nyc, or Istanbul. Regenerate the active npm, pnpm, or Yarn lockfile, rebuild CI images, devcontainers, workers, package-manager caches, and runtime artifacts that install dependencies, then rerun the FixVibe GitHub repo scan.

Review coverage scripts and any automation that accepts source or target paths. Keep untrusted request, webhook, job, repository, file-path, or environment text out of command arguments, and prefer tooling paths that invoke fixed executables with argv arrays instead of shell strings.