Headline
GHSA-54jw-jqr9-6cj9: Command injection in vagrant.js
All versions of the package vagrant.js are vulnerable to Command Injection via the boxAdd function due to improper input sanitization.
Command injection in vagrant.js
High severity GitHub Reviewed Published Jan 26, 2023 to the GitHub Advisory Database • Updated Jan 27, 2023
Related news
CVE-2022-25962: Snyk Vulnerability Database | Snyk
All versions of the package vagrant.js are vulnerable to Command Injection via the boxAdd function due to improper input sanitization.