GHSA-m2fc-9h5m-29cm
CRITICALCVE-2022-21186The package @acrontum/filesystem-template before 0.0.2 is vulnerable to Arbitrary Command Injection due to the fetchRepo API missing sanitization of the href field of external input.
- Affected
- < 0.0.2
- Fixed in
- 0.0.2
- Published
- 2022-08-06
- Source
- github