FixVibe

high

OS Command Injection in karma-mojo (CVE-2020-7626)

karma-mojo 1.0.1 and earlier is affected by CVE-2020-7626, an OS command injection. FixVibe GitHub repo scans flag affected karma-mojo versions in npm manifests and lockfiles.

CVE-2020-7626GHSA-pf8j-vhg8-xmc3CWE-78

Public advisories list karma-mojo 1.0.1 and earlier as affected by CVE-2020-7626 / GHSA-pf8j-vhg8-xmc3. The package is test-runner tooling, so the useful security question is whether a repository still installs the affected dependency in CI, developer, or test-runner environments where untrusted configuration could matter.

Impact

Affected karma-mojo versions can expose OS command-injection risk when attacker-controlled Karma/Mojo configuration reaches the vulnerable test-runner plugin. A dependency match is important patch-triage evidence for CI and developer hosts, but it is not the same as proving that a production web app is exploitable.

Covered by FixVibe

FixVibe's GitHub repo scans flag npm manifests or lockfiles that resolve karma-mojo to 1.0.1 or earlier, showing the package, file, line, version and advisory IDs so you can prioritize cleanup.

Remediation

Public advisories do not list a patched karma-mojo release. Remove karma-mojo or replace the Karma/Mojo integration with maintained test tooling, regenerate the active npm, pnpm, or Yarn lockfile, and rebuild CI images, devcontainers, package-manager caches, and test-runner artifacts that install dependencies.

Review untrusted pull-request and CI workflows so untrusted code cannot control Karma/Mojo configuration while repository secrets or trusted host access are available. After cleanup, rerun the FixVibe GitHub repo scan to confirm the affected dependency evidence is gone.