Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-795w-7426-m94j: stoqey/gnuplot is vulnerable to command injection

An issue found in Stoqey gnuplot v.0.0.3 and earlier allows attackers to execute arbitrary code via the src/index.ts, plotCallack, child_process, and/or filePath parameter(s).

ghsa
#git

stoqey/gnuplot is vulnerable to command injection

High severity GitHub Reviewed Published Mar 10, 2023 to the GitHub Advisory Database • Updated Mar 10, 2023

Related news

CVE-2021-33360: Checkmarx Advisory

An issue found in Stoqey gnuplot v.0.0.3 and earlier allows attackers to execute arbitrary code via the src/index.ts, plotCallack, child_process, and/or filePath parameter(s).