CVE-2020-7614
07.04.2020, 14:15
npm-programmatic through 0.0.12 is vulnerable to Command Injection.The packages and option properties are concatenated together without any validation and are used by the 'exec' function directly.Enginsight
Vendor | Product | Version |
---|---|---|
npm-programmatic_project | npm-programmatic | 𝑥 ≤ 0.0.12 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration