Vulnerability Report: GO-2022-0414
- CVE-2022-21235, GHSA-6635-c626-vj4r
- Affects: github.com/Masterminds/vcs
- Published: Jul 01, 2022
- Modified: May 20, 2024
Passing untrusted inputs to VCS functions can permit an attacker to execute arbitrary commands. The vcs package executes version control commands with user-provided arguments. These arguments can be interpreted as command-line flags, which can be used to perform command injection.
Affected Packages
-
PathGo VersionsSymbols
-
before v1.13.3
Aliases
References
Credits
- Alessio Della Libera of Snyk Research Team
Feedback
See anything missing or incorrect?
Suggest an edit to this report.