GHSA-cq77-8jpx-892g
HIGHCVE-2021-23381This affects all versions of package killing up to and including 1.0.6. If attacker-controlled user input is given, it is possible for an attacker to execute arbitrary commands. This is due to use of the childprocess exec function without input sanitization.
- Affected
- <= 1.0.6
- Fixed in
- not stated
- Weakness
- CWE-77
- Published
- 2021-05-06
- Source
- github