VDB
Sign up
MEDIUM

GHSA-4859-gpc7-4j66

Command Injection in dot

Details

All versions of dot are vulnerable to Command Injection. The template compilation may execute arbitrary commands if an attacker can inject code in the template or if a Prototype Pollution-like vulnerability can be exploited to alter an Object's prototype.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/dot
Introduced in: 0

No fixed version published yet for dot (npm). Pin to a known-safe version or switch to an alternative.

References