VDB
Sign up
—

PYSEC-2022-204

Quick fix

PYSEC-2022-204 — cookiecutter: upgrade to the fixed version with the command below.

pip install --upgrade 'cookiecutter>=fdffddb31fd2b46344dfa317531ff155e7999f77'

Details

The package cookiecutter before 2.1.1 are vulnerable to Command Injection via hg argument injection. When calling the cookiecutter function from Python code with the checkout parameter, it is passed to the hg checkout command in a way that additional flags can be set. The additional flags can be used to perform a command injection.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/cookiecutter
Introduced in: 0Fixed in: fdffddb31fd2b46344dfa317531ff155e7999f77
Fixpip install --upgrade 'cookiecutter>=fdffddb31fd2b46344dfa317531ff155e7999f77'

References