CRITICAL 9.8
GHSA-68mc-h6h8-79wj
YouTransfer has an issue in the sendmail transport integration that allows arbitrary code execution
Details
An issue in the sendmail transport integration component of YouTransfer v1.0.6 allows attackers to execute arbitrary code via supplying a crafted request.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm / youtransfer
Introduced in:
0 No fixed version published yet for youtransfer (npm). Pin to a known-safe version or switch to an alternative.