GHSA-vr9x-mm65-2438

Suggest an improvement
Source
https://github.com/advisories/GHSA-vr9x-mm65-2438
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/10/GHSA-vr9x-mm65-2438/GHSA-vr9x-mm65-2438.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-vr9x-mm65-2438
Aliases
  • CVE-2020-8178
Withdrawn
2020-10-19T18:55:38Z
Published
2020-10-08T21:38:51Z
Modified
2026-09-10T03:48:59Z
Summary
Command Injection in jison
Details

Withdrawn: This vulnerability is not present in the released npm package. Rather the vulnerable code is part of the repo, but not part of the package. See linked hackerone report for more details.

Insufficient input validation in npm package jison <= 0.4.18 may lead to OS command injection attacks.

Database specific
{
    "cwe_ids": [
        "CWE-78"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2020-10-08T21:36:44Z",
    "nvd_published_at": null,
    "severity": "HIGH"
}
References

Affected packages

npm / jison

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
0.4.18

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/10/GHSA-vr9x-mm65-2438/GHSA-vr9x-mm65-2438.json"