Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-jp45-65jw-94mj: heroku-env susceptible to command injection

A command injection vulnerability affects all versions of package heroku-env. The injection point is located in lib/get.js which is required by index.js.

ghsa
#vulnerability#js#git

heroku-env susceptible to command injection

Critical severity GitHub Reviewed Published Aug 3, 2022 • Updated Aug 10, 2022

Related news

CVE-2020-28437: Snyk Vulnerability Database | Snyk

This affects all versions of package heroku-env. The injection point is located in lib/get.js which is required by index.js.