VDB
Sign up
CRITICAL9.8

GHSA-7fw7-gh23-f832

Vulnerability in singleCrunch function leads to arbitrary code execution via filePath parameters

Details

aaptjs is a node wraper for aapt. An issue was discovered in the singleCrunch function in shenzhim aaptjs 1.3.1, allows attackers to execute arbitrary code via the filePath parameters.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/aaptjs
Introduced in: 0

No fixed version published yet for aaptjs (npm). Pin to a known-safe version or switch to an alternative.

References