MEDIUM
GHSA-g4w6-c99w-4wh7
BrowserStack Local vulnerable to Command Injection through logfile variable
Quick fix
GHSA-g4w6-c99w-4wh7 — browserstack-local: upgrade to the fixed version with the command below.
npm install browserstack-local@1.5.9Details
The Node.js package browserstack-local 1.5.8 contains a command injection vulnerability. This occurs because the logfile variable is not properly sanitized in lib/Local.js.
Are you affected?
Enter the version of the package you're using.