GHSA-m2fc-9h5m-29cm
Dashboard / Vulnerabilities / GHSA-m2fc-9h5m-29cm
Summary: @acrontum/filesystem-template vulnerable to Command Injection due to fetchRepo API missing sanitization
Details: The package @acrontum/filesystem-template before 0.0.2 is vulnerable to Arbitrary Command Injection due to the fetchRepo API missing sanitization of the href field of external input.
References: https://nvd.nist.gov/vuln/detail/CVE-2022-21186, https://github.com/acrontum/filesystem-template/issues/13, https://github.com/acrontum/filesystem-template/pull/14/commits/baeb727b60991ad82d9e63ac660883793abc0acc, https://github.com/acrontum/filesystem-template/commit/baeb727b60991ad82d9e63ac660883793abc0acc, https://github.com/acrontum/filesystem-template, https://security.snyk.io/vuln/SNYK-JS-ACRONTUMFILESYSTEMTEMPLATE-2419071
Affected packages
Package
Name: @acrontum/filesystem-template
Purl: pkg:npm/%40acrontum/filesystem-template
Affected ranges
Type: SEMVER
Events:
