Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-995x-33wq-8gc9: cycle-import-check vulnerable to Command Injection

The package cycle-import-check before version 1.3.2 is vulnerable to Command Injection via the writeFileToTmpDirAndOpenIt function due to improper user-input sanitization.

ghsa
#git

cycle-import-check vulnerable to Command Injection

High severity GitHub Reviewed Published Dec 14, 2022 • Updated Dec 14, 2022

Related news

CVE-2022-24377: Snyk Vulnerability Database | Snyk

The package cycle-import-check before 1.3.2 are vulnerable to Command Injection via the writeFileToTmpDirAndOpenIt function due to improper user-input sanitization.