pypi package report

Is @zowe/imperative safe?

1 known vulnerability, worst severity LOW.

cvss
3.3

how bad it is if exploited, out of 10

epss
0.30%

chance of exploitation in the next 30 days

xyz score
1.1

CyberXYZ composite, out of 10

fig. 01 — GHSA-6q8m-42qq-64r7, the advisory selected below

// advisories

GHSA-6q8m-42qq-64r7

LOWCVE-2021-4326

A vulnerability in Imperative framework which allows already-privileged local actors to execute arbitrary shell commands via plugin install/update commands, or maliciously formed environment variables. Impacts Zowe CLI.

Affected
< 4.18.10
Fixed in
4.18.10
Published
2023-03-01
Source
github

GHSANVDMITREreferencereferencereferencereference


// ai model usage

No published models are known to use this package.


Checked 2026-09-22 at 02:46 UTC. The most recent advisory here was published 2023-03-01. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is @zowe/imperative safe? pypi package security report | CyberXYZ