Dependency Confusion to RCE By Steiner254
npm install @wireframe-tool/pointivo-app-hostInternal package for the Pointivo App Host - Vulnerable To Dependency Confusion Resulting To RCE.
> ⚠️ This package name is a prove of an RCE by @Steiner254.
bash
npm install @wireframe-tool/pointivo-app-hostSecurity Proof of Concept
This package contains a non-malicious proof of remote code execution (RCE).
When installed or imported, it:
- Executes JavaScript code
- Writes a harmless file to
/tmp`