Описание
create-choo-app3 is vulnerable to Command Injection via the devInstall function
All versions of the package create-choo-app3 are vulnerable to Command Injection via the devInstall function due to improper user-input sanitization.
Пакеты
Наименование
create-choo-app3
npm
Затронутые версииВерсия исправления
<= 1.12.3
Отсутствует
Связанные уязвимости
CVSS3: 7.4
nvd
около 3 лет назад
All versions of the package create-choo-app3 are vulnerable to Command Injection via the devInstall function due to improper user-input sanitization.