ens-primary-name
Audited by Socket on Sep 24, 2026
2 alerts found:
Securityx2The script has a significant local JavaScript injection vulnerability: a crafted command-line ENS_NAME can escape the string literal passed to node -e and execute arbitrary code as the invoking user. Input is also inserted into a GraphQL/JSON request without escaping. The visible transaction behavior is consistent with setting an ENS reverse record; there is no clear evidence of intentional malware.
The script has a significant JavaScript injection vulnerability: crafted ENS_NAME or AVATAR_URL arguments can execute arbitrary code through node -e. It also constructs an unescaped GraphQL query and submits a wallet-authorized transaction. No explicit malware behavior is evident, but the script should not be used with untrusted arguments; pass values safely to Node rather than interpolating them into source code.