Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-vvh2-82c7-ppfg: network Arbitrary Command Injection vulnerability

Versions of the package network before 0.7.0 are vulnerable to Arbitrary Command Injection due to use of the child_process exec function without input sanitization. If (attacker-controlled) user input is given to the mac_address_for function of the package, it is possible for an attacker to execute arbitrary commands on the operating system that this package is being run on.

ghsa
#vulnerability#mac#git

network Arbitrary Command Injection vulnerability

High severity GitHub Reviewed Published Jan 30, 2024 to the GitHub Advisory Database • Updated Jan 30, 2024

ghsa: Latest News

GHSA-mj5r-x73q-fjw6: SPEmailHandler-PHP has Potential Abuse for Sending Arbitrary Emails