CRITICAL9.8
GHSA-h86x-mv66-gr5q
OS Command Injection in Locutus
Details
php/exec/escapeshellarg in Locutus PHP through 2.0.11 allows an attacker to achieve code execution.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/locutus
Introduced in:
0No fixed version published yet for locutus (npm). Pin to a known-safe version or switch to an alternative.