Command Injection
Published Dec 11, 2020
5.6
MEDIUMCVSS 3.1
EPSS 1.59%
Description
This affects the package node-notifier before 9.0.0. It allows an attacker to run arbitrary commands on Linux machines due to the options params not being sanitised when being passed an array.
Affected products
- Vendor n/a Product Node-Notifier Defaultn/a
- Version unspecifiedStatusaffectedConstraints<9.0.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Node-Notifier | n/a |
|
- < 8.0.1
No data.
Red Hat Automation Hub 4.2 for RHEL 7
automation-hub-0:4.2.2-1.el7pc
Fixed · RHSA-2021:0781
Red Hat Automation Hub 4.2 for RHEL 7
python-bleach-0:3.3.0-1.el7pc
Fixed · RHSA-2021:0781
Red Hat Automation Hub 4.2 for RHEL 7
python-bleach-allowlist-0:1.0.3-1.el7pc
Fixed · RHSA-2021:0781
Red Hat Automation Hub 4.2 for RHEL 7
python-galaxy-importer-0:0.2.15-1.el7pc
Fixed · RHSA-2021:0781
Red Hat Automation Hub 4.2 for RHEL 7
python-galaxy-ng-0:4.2.2-1.el7pc
Fixed · RHSA-2021:0781
Red Hat Automation Hub 4.2 for RHEL 7
python-pulp-ansible-1:0.5.6-1.el7pc
Fixed · RHSA-2021:0781
Red Hat Automation Hub 4.2 for RHEL 7
python3-django-0:2.2.18-1.el7pc
Fixed · RHSA-2021:0781
Red Hat Automation Hub 4.2 for RHEL 8
automation-hub-0:4.2.2-1.el8pc
Fixed · RHSA-2021:0781
Red Hat Automation Hub 4.2 for RHEL 8
python-bleach-0:3.3.0-1.el8pc
Fixed · RHSA-2021:0781
Red Hat Automation Hub 4.2 for RHEL 8
python-bleach-allowlist-0:1.0.3-1.el8pc
Fixed · RHSA-2021:0781
Red Hat Automation Hub 4.2 for RHEL 8
python-galaxy-importer-0:0.2.15-1.el8pc
Fixed · RHSA-2021:0781
Red Hat Automation Hub 4.2 for RHEL 8
python-galaxy-ng-0:4.2.2-1.el8pc
Fixed · RHSA-2021:0781
Red Hat Automation Hub 4.2 for RHEL 8
python-pulp-ansible-1:0.5.6-1.el8pc
Fixed · RHSA-2021:0781
Red Hat Automation Hub 4.2 for RHEL 8
python3-django-0:2.2.18-1.el8pc
Fixed · RHSA-2021:0781
OpenShift Service Mesh 1
kiali
Out of support scope
OpenShift Service Mesh 1
servicemesh-grafana
Out of support scope
OpenShift Service Mesh 1
servicemesh-prometheus
Out of support scope
OpenShift Service Mesh 2.0
servicemesh-grafana
Will not fix
OpenShift Service Mesh 2.0
servicemesh-prometheus
Will not fix
Red Hat Advanced Cluster Management for Kubernetes 2
node-notifier
Out of support scope
Red Hat OpenShift Container Platform 4
openshift4/ose-console
Will not fix
Red Hat OpenShift Container Platform 4
openshift4/ose-grafana
Will not fix
Red Hat OpenShift Container Platform 4
openshift4/ose-prometheus
Will not fix
Red Hat OpenShift Container Platform 4
openshift4/ose-thanos-rhel8
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Automation Hub 4.2 for RHEL 7 | automation-hub-0:4.2.2-1.el7pc | Fixed | RHSA-2021:0781 |
| Red Hat Automation Hub 4.2 for RHEL 7 | python-bleach-0:3.3.0-1.el7pc | Fixed | RHSA-2021:0781 |
| Red Hat Automation Hub 4.2 for RHEL 7 | python-bleach-allowlist-0:1.0.3-1.el7pc | Fixed | RHSA-2021:0781 |
| Red Hat Automation Hub 4.2 for RHEL 7 | python-galaxy-importer-0:0.2.15-1.el7pc | Fixed | RHSA-2021:0781 |
| Red Hat Automation Hub 4.2 for RHEL 7 | python-galaxy-ng-0:4.2.2-1.el7pc | Fixed | RHSA-2021:0781 |
| Red Hat Automation Hub 4.2 for RHEL 7 | python-pulp-ansible-1:0.5.6-1.el7pc | Fixed | RHSA-2021:0781 |
| Red Hat Automation Hub 4.2 for RHEL 7 | python3-django-0:2.2.18-1.el7pc | Fixed | RHSA-2021:0781 |
| Red Hat Automation Hub 4.2 for RHEL 8 | automation-hub-0:4.2.2-1.el8pc | Fixed | RHSA-2021:0781 |
| Red Hat Automation Hub 4.2 for RHEL 8 | python-bleach-0:3.3.0-1.el8pc | Fixed | RHSA-2021:0781 |
| Red Hat Automation Hub 4.2 for RHEL 8 | python-bleach-allowlist-0:1.0.3-1.el8pc | Fixed | RHSA-2021:0781 |
| Red Hat Automation Hub 4.2 for RHEL 8 | python-galaxy-importer-0:0.2.15-1.el8pc | Fixed | RHSA-2021:0781 |
| Red Hat Automation Hub 4.2 for RHEL 8 | python-galaxy-ng-0:4.2.2-1.el8pc | Fixed | RHSA-2021:0781 |
| Red Hat Automation Hub 4.2 for RHEL 8 | python-pulp-ansible-1:0.5.6-1.el8pc | Fixed | RHSA-2021:0781 |
| Red Hat Automation Hub 4.2 for RHEL 8 | python3-django-0:2.2.18-1.el8pc | Fixed | RHSA-2021:0781 |
| OpenShift Service Mesh 1 | kiali | Out of support scope | n/a |
| OpenShift Service Mesh 1 | servicemesh-grafana | Out of support scope | n/a |
| OpenShift Service Mesh 1 | servicemesh-prometheus | Out of support scope | n/a |
| OpenShift Service Mesh 2.0 | servicemesh-grafana | Will not fix | n/a |
| OpenShift Service Mesh 2.0 | servicemesh-prometheus | Will not fix | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | node-notifier | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-console | Will not fix | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-grafana | Will not fix | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-prometheus | Will not fix | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-thanos-rhel8 | Will not fix | n/a |
node-notifier
npm
Introduced 0 Fixed 8.0.1
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | node-notifier | 0 | 8.0.1 |
Remediation
Red Hat statement
Whilst the OpenShift ServiceMesh (OSSM) and OpenShift Container Platform (OCP) containers include the vulnerable nodejs-node-notifier library, the successful exploitation requires additional packages on the node (like desktop notification library) which are not part of the OpenShift ServiceMesh or OpenShift Container Platform products. Additionally access to the vulnerable nodejs-node-notifier library is restricted to authenticated users only (OpenShift OAuth authentication). Therefore these OSSM and OCP components have been marked as wont-fix and may be addressed in a future updates. OpenShift ServiceMesh (OSSM) 1.1 is out of support scope for Moderate and Low impact vulnerabilities, hence is marked Out Of Support Scope. The nodejs-notifier library was present in Red Hat Advanced Cluster Management for Kubernetes version 2.0, but is no longer used since version 2.1. Customers are advised to upgrade to the latest version which is fully supported, does not include this vulnerability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (12 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 1.59% (0.01594) | 74.86th | v5 (v2026.06.15) |
| Sep 20, 2026 | 1.59% (0.01594) | 74.61th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.20% (0.00198) | 57.77th | v3 (v2023.03.01) |
| Sep 3, 2023 | 0.20% (0.00198) | 56.90th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.13% (0.00130) | 46.16th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.95% (0.00954) | 36.37th | v2 (v2022.01.01) |
| Apr 1, 2022 | 0.95% (0.00954) | 32.50th | v2 (v2022.01.01) |
| Feb 4, 2022 | 5.74% (0.05736) | 77.22th | v2 (v2022.01.01) |
| Feb 3, 2022 | 3.63% (0.03630) | 71.73th | v1 |
| Jan 6, 2022 | 3.63% (0.03630) | 71.48th | v1 |
| Jan 5, 2022 | 0.83% (0.00833) | 58.90th | v5 (v2026.06.15) |
| Apr 14, 2021 | 0.83% (0.00833) | 0.00th | v1 |
References (9)
- https://access.redhat.com/security/cve/CVE-2020-7789 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1906853 Issue Tracking
- https://github.com/advisories/GHSA-5fw9-fq32-wv5p Advisory
- https://github.com/mikaelbr/node-notifier/blob/master/lib/utils.js%23L303 x_refsource_MISCBroken Link
- https://github.com/mikaelbr/node-notifier/commit/5d62799dab88505a709cd032653b2320c5813fce
- https://nvd.nist.gov/vuln/detail/CVE-2020-7789
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1050371 x_refsource_MISCThird Party Advisory
- https://snyk.io/vuln/SNYK-JS-NODENOTIFIER-1035794 x_refsource_MISCThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-7789
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-7789 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1906853 | Issue Tracking | |
| https://github.com/advisories/GHSA-5fw9-fq32-wv5p | Advisory | |
| https://github.com/mikaelbr/node-notifier/blob/master/lib/utils.js%23L303 | x_refsource_MISCBroken Link | |
| https://github.com/mikaelbr/node-notifier/commit/5d62799dab88505a709cd032653b2320c5813fce | ||
| https://nvd.nist.gov/vuln/detail/CVE-2020-7789 | ||
| https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1050371 | x_refsource_MISCThird Party Advisory | |
| https://snyk.io/vuln/SNYK-JS-NODENOTIFIER-1035794 | x_refsource_MISCThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2020-7789 |
Change history (0)
No recorded changes yet.