VDB
Sign up
HIGH7.8

GHSA-3p94-vj97-fm4q

OS Command Injection in fsa

Details

fsa through 0.5.1 is vulnerable to Command Injection. The first argument of 'execGitCommand()', located within 'lib/rep.js#63' can be controlled by users without any sanitization to inject arbitrary commands.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/fsa
Introduced in: 0

No fixed version published yet for fsa (npm). Pin to a known-safe version or switch to an alternative.

References