Public advisories list node-key-sender 1.0.11 and earlier as affected by CVE-2020-7627 / GHSA-4xrw-wvmq-8jmh. The package is used for keyboard and desktop automation from Node.js, so the useful security question is whether a repository still installs an affected release on a trusted automation host, CI worker, developer machine, or runtime image.
Impact
Affected versions can expose operating-system command-injection risk when unsafe input reaches keyboard automation parameters. A dependency match is meaningful triage evidence for automation hosts and developer tooling, but it does not by itself prove that a deployed service executes the package or that untrusted input can reach the vulnerable path.
Covered by FixVibe
FixVibe's GitHub repo scans flag npm manifests and lockfiles that resolve node-key-sender versions in the affected range (<=1.0.11), showing the file, line, version and remediation target.
Remediation
Public advisories do not list a patched node-key-sender release. Remove the package or replace it with maintained automation tooling, regenerate the active package-lock.json, npm-shrinkwrap.json, pnpm-lock.yaml, or yarn.lock, and rebuild every runtime image, desktop automation host, worker, devcontainer, CI image, or package-manager cache that installs dependencies.
Review call sites that build automation parameters from request, webhook, job, user, or environment text. Keep desktop automation isolated from untrusted input and secret-bearing CI jobs, then rerun the FixVibe GitHub repo scan to confirm the affected package is gone from the dependency tree.
