CRITICAL9.8
GHSA-r496-7hgp-53wf
Vulnerability in dump function leads to arbitrary code execution via filePath parameters
Details
aaptjs is a node wraper for aapt. An issue was discovered in the dump function in shenzhim aaptjs 1.3.1, allows attackers to execute arbitrary code via the filePath parameters.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/aaptjs
Introduced in:
0No fixed version published yet for aaptjs (npm). Pin to a known-safe version or switch to an alternative.