Christopher Thielen Check-Peer-Dependencies OS Command Injection Vulnerability

Vulnerability

A command injection vulnerability has been identified in Christopher Thielen's 'check-peer-dependencies' package, specifically in version 4.3.4. The issue arises in the 'peerDependencies' handling, where package names are extracted from 'package.json' and interpolated into shell commands. This flaw allows for the execution of arbitrary operating system commands, potentially initiated remotely. The vulnerability was reported to the project, but no response has been received.

Impact

Exploitation of this vulnerability allows for arbitrary OS command execution, with the potential for remote exploitation.

Reproduction

The vulnerability can be reproduced by creating a 'package.json' file with malicious 'peerDependencies' that include shell metacharacters. When 'check-peer-dependencies' is run with the '--findSolutions' or '--install' options, the tool will execute commands that include the injected metacharacters, leading to command injection.

Added: Jul 8, 2026, 2:52 PM
Updated: Jul 8, 2026, 2:52 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
4.2
remediation
0.0
relevance
9.6
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.