Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-vvj3-85vf-fgmw: global-modules-path Command Injection vulnerability

Versions of the package global-modules-path before 3.0.0 are vulnerable to Command Injection due to missing input sanitization or other checks and sandboxes being employed to the getPath function.

ghsa
#vulnerability#git

global-modules-path Command Injection vulnerability

High severity GitHub Reviewed Published Jan 13, 2023 • Updated Jan 13, 2023

Related news

CVE-2022-21191

Versions of the package global-modules-path before 3.0.0 are vulnerable to Command Injection due to missing input sanitization or other checks and sandboxes being employed to the getPath function.

ghsa: Latest News

GHSA-xc93-q32j-cpcg: Jellysweep uses uncontrolled data in image cache API endpoint