Headline
GHSA-8h3g-hcwp-6hxq: semver-tags is vulnerable to Command Injection via the getGitTagsRemote function
All versions of the package semver-tags are vulnerable to Command Injection via the getGitTagsRemote function due to improper input sanitization.
semver-tags is vulnerable to Command Injection via the getGitTagsRemote function
High severity GitHub Reviewed Published Feb 6, 2023 to the GitHub Advisory Database • Updated Feb 7, 2023
Related news
CVE-2022-25853
All versions of the package semver-tags are vulnerable to Command Injection via the getGitTagsRemote function due to improper input sanitization.