VDB
Sign up
HIGH7.3

GHSA-qjg4-w4c6-f6c6

Command injection in mversion

Quick fix

GHSA-qjg4-w4c6-f6c6 — mversion: upgrade to the fixed version with the command below.

npm install mversion@2.0.0

Details

### Impact This issue may lead to remote code execution if a client of the library calls the vulnerable method with untrusted input.

### Patches Patched by version 2.0.0. Previous releases are deprecated in npm.

### Workarounds Make sure to escape git commit messages when using the commitMessage option for the update function.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/mversion
Introduced in: 0Fixed in: 2.0.0
Fixnpm install mversion@2.0.0

References