Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-54jw-jqr9-6cj9: Command injection in vagrant.js

All versions of the package vagrant.js are vulnerable to Command Injection via the boxAdd function due to improper input sanitization.

ghsa
#js#git

Command injection in vagrant.js

High severity GitHub Reviewed Published Jan 26, 2023 to the GitHub Advisory Database • Updated Jan 27, 2023

Related news

CVE-2022-25962: Snyk Vulnerability Database | Snyk

All versions of the package vagrant.js are vulnerable to Command Injection via the boxAdd function due to improper input sanitization.