Vulnerabilities/

chrome-launcher subject to OS Command Injection

Severity:
High

Description

chrome-launcher prior to 0.13.2 is subject to OS Command Injection via the $HOME environment variable in Linux operating systems. This issue is patched in version 0.13.2.

Recommendation

Update the chrome-launcher package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
chrome-launcher
Anything's wrong? Let us know Last updated on September 06, 2023

This issue is available in SmartScanner Professional

See Pricing