PT-2021-16985 · Unknown · Eslint-Fixer

Published

2021-03-18

·

Updated

2024-08-03

·

CVE-2021-26275

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions eslint-fixer versions 0.1.5 and earlier
Description The issue allows command injection via shell metacharacters to the fix function. This affects products that are no longer supported by the maintainer. The ozum/eslint-fixer GitHub repository has been intentionally deleted.
Recommendations For versions 0.1.5 and earlier, as a temporary workaround, consider disabling the fix function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2021-26275
GHSA-45W5-PVR8-4RH5

Affected Products

Eslint-Fixer