VDB
Sign up
LOW3.8

GHSA-77qv-gh6f-pgh4

Command Injection in Limdu

Quick fix

GHSA-77qv-gh6f-pgh4 — limdu: upgrade to the fixed version with the command below.

npm install limdu@0.9.5

Details

### Impact The `trainBatch` function has a command injection vulnerability. Clients of the Limdu library are unlikely to be aware of this, so they might unwittingly write code that contains a vulnerability.

### Patches Patched in version 0.9.5.

### Workarounds Do not use trainBatch with classifiers that rely on shell execution, such as SVM Perf, SVM Linear or Adaboost

### References No

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/limdu
Introduced in: 0Fixed in: 0.9.5
Fixnpm install limdu@0.9.5

References