GHSA-6722-xvq8-3254

Suggest an improvement
Source
https://github.com/advisories/GHSA-6722-xvq8-3254
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/03/GHSA-6722-xvq8-3254/GHSA-6722-xvq8-3254.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-6722-xvq8-3254
Aliases
  • CVE-2023-26107
Published
2023-03-06T06:30:18Z
Modified
2023-11-08T04:11:57.954673Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
SketchSVG Arbitrary Code Injection vulnerability
Details

All versions of the package sketchsvg are vulnerable to Arbitrary Code Injection when invoking shell.exec without sanitization nor parametrization while concatenating the current directory as part of the command string.

Database specific
{
    "github_reviewed_at": "2023-03-07T20:30:33Z",
    "github_reviewed": true,
    "severity": "HIGH",
    "nvd_published_at": "2023-03-06T05:15:00Z",
    "cwe_ids": [
        "CWE-94"
    ]
}
References

Affected packages

npm / sketchsvg

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
0.0.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/03/GHSA-6722-xvq8-3254/GHSA-6722-xvq8-3254.json"