Security readout for executives and security teams
Plain-English summary
CVE-2021-23330 is a critical command injection issue in the JavaScript package launchpad. If an application uses the vulnerable stop functionality with attacker-controlled input, an attacker may be able to run system commands. The source bundle says all versions are vulnerable, but it does not name a fixed release.
Executive priority
Prioritize this for same-cycle dependency review if launchpad is present in production or automation. The CVSS score is critical, but urgency depends on whether the vulnerable functionality is reachable from untrusted input. If launchpad is absent, record non-exposure and monitor vendor guidance.
Technical view
The CVE describes command injection in package launchpad via stop, with CVSS 3.1 score 9.8: network-accessible, low complexity, no privileges, no user interaction, and high confidentiality, integrity, and availability impact. No CWE is listed. Patch details are not included in the provided bundle.
Likely exposure
Exposure is most likely in Node.js applications, build tooling, or internal automation that depends on the launchpad package and exposes stop behavior to untrusted input or remote requests. The bundle provides no CPEs, so dependency inventory is the primary exposure check.
Exploitation context
The CVE is not listed as CISA KEV in the provided bundle, and no cited source in the bundle confirms active exploitation. Treat it as high-impact because the vulnerability class can allow command execution, but do not assume exploitation without environment-specific evidence.
Researcher notes
Evidence is limited to CVE, Snyk, and upstream GitHub references. The bundle states all versions are vulnerable but does not provide a fixed version, affected CPEs, CWE, proof of exploitation, or operational indicators. Verify the exact npm package identity before scoping.
Mitigation direction
- Inventory applications and tooling for the launchpad package.
- Review Snyk and the GitHub PR for vendor-confirmed remediation details.
- Update only to a vendor-confirmed fixed version if available.
- Remove or replace launchpad where remediation cannot be confirmed.
- Avoid exposing stop-related behavior to untrusted users or inputs.
Validation and detection
- Search dependency manifests and lockfiles for launchpad.
- Confirm whether vulnerable stop functionality is reachable in deployed code.
- Check Snyk and upstream GitHub references for fixed-version guidance.
- Review runtime logs for unexpected stop-related errors or process activity.
- Document systems where remediation is unavailable or deferred.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
Execution behavior lookup
The CVE wording references code or command execution, so execution technique review may help defensive triage. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
Open ATT&CK lookupCVE-2021-23330 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Critical
- CVSS
- 9.8 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H3.95.9Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
9.8CriticalVector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source materials
- CVE List V5 sourceCVE List V5
- https://snyk.io/vuln/SNYK-JS-LAUNCHPAD-1044065CVE reference · x_refsource_MISC
- https://github.com/bitovi/launchpad/issues/123%23issuecomment-732188118CVE reference · x_refsource_MISC
- https://github.com/bitovi/launchpad/pull/124CVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
