Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-rphm-c8gw-3r38: OS Command Injection in lifion-verify-deps

lifion-verify-dependencies through 1.1.0 is vulnerable to OS command injection via a crafted dependency name on the scanned project’s package.json file.

ghsa
#js#git

OS Command Injection in lifion-verify-deps

High severity GitHub Reviewed Published Jun 3, 2022 • Updated Jun 3, 2022

Related news

CVE-2021-34078: Checkmarx Advisory

lifion-verify-dependencies through 1.1.0 is vulnerable to OS command injection via a crafted dependency name on the scanned project's package.json file.