Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-f259-h6m8-hm8m: exec-local-bin vulnerable to Command Injection

Versions of the package exec-local-bin before 1.2.0 are vulnerable to Command Injection via the theProcess() functionality due to improper user-input sanitization.

ghsa
#git

exec-local-bin vulnerable to Command Injection

High severity GitHub Reviewed Published Jan 6, 2023 • Updated Jan 9, 2023

Related news

CVE-2022-25923: Snyk Vulnerability Database | Snyk

Versions of the package exec-local-bin before 1.2.0 are vulnerable to Command Injection via the theProcess() functionality due to improper user-input sanitization.