The op-browser npm package has an OS command-injection advisory tracked as CVE-2020-7625 and GHSA-3hq6-rmv7-39vh. GitHub Advisory and OSV list npm package op-browser versions up to and including 1.0.9 as affected, with no patched version listed [S2][S3]. The npm registry still shows 1.0.9 as the latest published version [S4].
Impact
If an application, worker, CI job, or browser-automation host calls op-browser with attacker-controlled URL, proxy, PAC, browser-name, or launch data, affected versions can let that input cross an operating-system command boundary [S1][S2]. The operational risk depends on whether the package is installed in the deployed runtime or trusted automation host, and whether untrusted input can reach the vulnerable browser-launch path.
Root Cause
The advisory is classified as CWE-78: improper neutralization of special elements used in an OS command [S1]. Affected op-browser versions pass browser-launch inputs into operating-system process execution behavior without sufficient protection for command boundaries [S2][S3].
How FixVibe covers it
FixVibe's GitHub repo scans flag package.json, package-lock.json, npm-shrinkwrap.json, pnpm-lock.yaml, or yarn.lock entries that resolve op-browser in the affected range, so you can remove or replace the package and review any browser-launch call sites.
Fixes
Remove op-browser or replace it with maintained browser-launch tooling that invokes fixed executables with argument arrays instead of shell strings. Regenerate the active npm, pnpm, or Yarn lockfile, rebuild every runtime image, browser-automation host, worker, devcontainer, CI image, and package-manager cache that installs dependencies, and rerun the FixVibe GitHub repo scan.
Review browser-launch call sites so request, webhook, job, URL, proxy, PAC, browser-name, or environment text cannot directly shape command arguments. Keep verification to dependency-tree checks, rebuilt-artifact evidence, source review, and benign smoke tests; do not add exploit payloads or command-execution proof fixtures.
