LOW3.8
GHSA-77qv-gh6f-pgh4
Command Injection in Limdu
Quick fix
GHSA-77qv-gh6f-pgh4 — limdu: upgrade to the fixed version with the command below.
npm install limdu@0.9.5Details
### Impact The `trainBatch` function has a command injection vulnerability. Clients of the Limdu library are unlikely to be aware of this, so they might unwittingly write code that contains a vulnerability.
### Patches Patched in version 0.9.5.
### Workarounds Do not use trainBatch with classifiers that rely on shell execution, such as SVM Perf, SVM Linear or Adaboost
### References No
Are you affected?
Enter the version of the package you're using.