CVE-2022-21186

CRITICAL9.8EPSS 6.6%

@acrontum/filesystem-template vulnerable to Command Injection due to fetchRepo API missing sanitization

Published: 8/6/2022Modified: 11/8/2023
Also known as:GHSA-m2fc-9h5m-29cm

Description

The package @acrontum/filesystem-template before 0.0.2 is vulnerable to Arbitrary Command Injection due to the fetchRepo API missing sanitization of the href field of external input.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References (6)