An issue in tiagorlampert CHAOS before 1b451cf62582295b7225caf5a7b506f0bad56f6b and 24c9e109b5be34df7b2bce8368eae669c481ed5e allows a remote attacker to execute arbitrary code via the unsafe concatenation of the filename argument into the buildStr string without any sanitization or filtering.
{
"severity": "CRITICAL",
"github_reviewed": true,
"cwe_ids": [
"CWE-78"
],
"nvd_published_at": "2024-05-07T14:15:10Z",
"github_reviewed_at": "2024-05-07T16:53:55Z"
}