GHSA-6m4r-m3gc-h4r5
CRITICALCVE-2020-7629install-package through 0.4.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the options argument.
- Affected
- <= 0.4.0
- Fixed in
- not stated
- Weakness
- CWE-78
- Published
- 2022-02-10
- Source
- github