PT-2022-14910 · Npm · @Acrontum/Filesystem-Template

Feng Xiao

+1

·

Published

2022-08-05

·

Updated

2023-08-08

·

CVE-2022-21186

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions @acrontum/filesystem-template versions prior to 0.0.2
Description The issue is related to Arbitrary Command Injection due to the fetchRepo API missing sanitization of the href field of external input. This allows for potential command injection attacks.
Recommendations For versions prior to 0.0.2, update to version 0.0.2 or later to resolve the issue. As a temporary workaround, consider disabling the fetchRepo API or restricting access to it until a patch is available. Avoid using the href field in the affected API endpoint until the issue is resolved.

Exploit

Fix

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2022-21186
GHSA-M2FC-9H5M-29CM

Affected Products

@Acrontum/Filesystem-Template