Affected versions of summit allow attackers to execute arbitrary commands via collection names when using the PouchDB driver.
No direct patch is available at this time.
Currently, the best option to mitigate the issue is to avoid using the PouchDB driver, as the package author has abandoned this feature entirely.
{
"cwe_ids": [
"CWE-94"
],
"github_reviewed": true,
"github_reviewed_at": "2020-08-31T18:18:59Z",
"nvd_published_at": "2018-06-04T19:29:01Z",
"severity": "CRITICAL"
}