VDB
Sign up
CRITICAL9.8

GHSA-m7p2-ghfh-pjvx

Vulnerability in crunch function leads to arbitrary code execution via filePath parameters

Details

aaptjs is a node wraper for aapt. An issue was discovered in the crunch function in shenzhim aaptjs 1.3.1, allows attackers to execute arbitrary code via the filePath parameters.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/aaptjs
Introduced in: 0

No fixed version published yet for aaptjs (npm). Pin to a known-safe version or switch to an alternative.

References