MEDIUM
GHSA-4859-gpc7-4j66
Command Injection in dot
Details
All versions of dot are vulnerable to Command Injection. The template compilation may execute arbitrary commands if an attacker can inject code in the template or if a Prototype Pollution-like vulnerability can be exploited to alter an Object's prototype.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/dot
Introduced in:
0No fixed version published yet for dot (npm). Pin to a known-safe version or switch to an alternative.