HIGH7.3
GHSA-qjg4-w4c6-f6c6
Command injection in mversion
Quick fix
GHSA-qjg4-w4c6-f6c6 — mversion: upgrade to the fixed version with the command below.
npm install mversion@2.0.0Details
### Impact This issue may lead to remote code execution if a client of the library calls the vulnerable method with untrusted input.
### Patches Patched by version 2.0.0. Previous releases are deprecated in npm.
### Workarounds Make sure to escape git commit messages when using the commitMessage option for the update function.
Are you affected?
Enter the version of the package you're using.