Critical severity vulnerability that affects dns-sync
        
  Critical severity
        
          GitHub Reviewed
      
        Published
          Jul 26, 2018 
          to the GitHub Advisory Database
          •
          Updated Jan 9, 2023 
      
  
  
      Withdrawn
      This advisory was withdrawn on Jun 17, 2020
  
    
      Description
        Published to the GitHub Advisory Database
      Jul 26, 2018 
    
  
        Reviewed
      Jun 17, 2020 
    
  
        Withdrawn
      Jun 17, 2020 
    
  
        Last updated
      Jan 9, 2023 
    
  
Withdrawn, accidental duplicate publish.
The dns-sync module before 0.1.1 for node.js allows context-dependent attackers to execute arbitrary commands via shell metacharacters in the first argument to the resolve API function.
References