FixVibe

high

OS Command Injection in strong-nginx-controller (CVE-2020-7621)

The strong-nginx-controller npm package is affected by CVE-2020-7621 / GHSA-4v9w-pvwr-38h3 through version 1.0.2. FixVibe GitHub repo scans flag affected versions in npm manifests and lockfiles.

CVE-2020-7621GHSA-4v9w-pvwr-38h3CWE-78

An OS command injection advisory exists in the strong-nginx-controller npm package [S2]. CVE-2020-7621 affects versions through 1.0.2 [S1], and the reviewed GitHub Advisory lists no patched version [S2].

Impact

When the affected package is installed in a deployed controller or automation host, unsafe command construction in NGINX management flows can create operating-system command execution risk [S1]. The practical impact depends on where the package is used, what privileges the process has, and whether untrusted deployment, request, webhook, or environment data can reach the command helper.

Root Cause

The issue is tracked as CWE-78, improper neutralization of special elements used in an OS command [S1]. Public advisory sources describe the vulnerable behavior in the package command helper [S2][S3].

Covered by FixVibe

FixVibe's GitHub repo scans flag npm dependency evidence for strong-nginx-controller in the affected range, with the advisory IDs and remediation path so you can remove or replace it before it reaches controller, CI, deployment, or automation hosts.

Remediation

There is no patched version listed in the reviewed advisory [S2]. Remove strong-nginx-controller or replace it with maintained NGINX orchestration tooling, regenerate npm, pnpm, or Yarn lockfiles, rebuild images and CI caches that install dependencies, and rerun the repo scan. Review any controller call sites so untrusted request, webhook, deployment, or environment data cannot reach NGINX management command arguments.