CVE-2023-26107
06.03.2023, 05:15
All versions of the package sketchsvg are vulnerable to Arbitrary Code Injection when invoking shell.exec without sanitization nor parametrization while concatenating the current directory as part of the command string.
| Vendor | Product | Version |
|---|---|---|
| ebay | sketchsvg | - |
𝑥
= Vulnerable software versions
References