Command Injection in open
Critical severity
GitHub Reviewed
Published
Jun 20, 2019
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Reviewed
Jun 20, 2019
Published to the GitHub Advisory Database
Jun 20, 2019
Last updated
Jan 9, 2023
Versions of
open
before 6.0.0 are vulnerable to command injection when unsanitized user input is passed in.The package does come with the following warning in the readme:
Recommendation
open
is now the deprecatedopn
package. Upgrading to the latest version is likely have unwanted effects since it now has a very different API but will prevent this vulnerability.References