VDB
Sign up
MEDIUM

GHSA-g4w6-c99w-4wh7

BrowserStack Local vulnerable to Command Injection through logfile variable

Quick fix

GHSA-g4w6-c99w-4wh7 — browserstack-local: upgrade to the fixed version with the command below.

npm install browserstack-local@1.5.9

Details

The Node.js package browserstack-local 1.5.8 contains a command injection vulnerability. This occurs because the logfile variable is not properly sanitized in lib/Local.js.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/browserstack-local
Introduced in: 0Fixed in: 1.5.9
Fixnpm install browserstack-local@1.5.9

References