FixVibe

high

OS Command Injection in node-key-sender (CVE-2020-7627)

FixVibe GitHub repo scans can now flag npm manifests and lockfiles that resolve node-key-sender versions affected by CVE-2020-7627 / GHSA-4xrw-wvmq-8jmh as version-based advisory evidence.

CVE-2020-7627GHSA-4xrw-wvmq-8jmhCWE-78

Public advisories list node-key-sender 1.0.11 and earlier as affected by CVE-2020-7627 / GHSA-4xrw-wvmq-8jmh. The package is used for keyboard and desktop automation from Node.js, so the useful security question is whether a repository still installs an affected release on a trusted automation host, CI worker, developer machine, or runtime image.

Impact

Affected versions can expose operating-system command-injection risk when unsafe input reaches keyboard automation parameters. A dependency match is meaningful triage evidence for automation hosts and developer tooling, but it does not by itself prove that a deployed service executes the package or that untrusted input can reach the vulnerable path.

Covered by FixVibe

FixVibe's GitHub repo scans flag npm manifests and lockfiles that resolve node-key-sender versions in the affected range (<=1.0.11), showing the file, line, version and remediation target.

Remediation

Public advisories do not list a patched node-key-sender release. Remove the package or replace it with maintained automation tooling, regenerate the active package-lock.json, npm-shrinkwrap.json, pnpm-lock.yaml, or yarn.lock, and rebuild every runtime image, desktop automation host, worker, devcontainer, CI image, or package-manager cache that installs dependencies.

Review call sites that build automation parameters from request, webhook, job, user, or environment text. Keep desktop automation isolated from untrusted input and secret-bearing CI jobs, then rerun the FixVibe GitHub repo scan to confirm the affected package is gone from the dependency tree.