Vulnerabilities/

Command Injection in ascii-art

Severity:
Low

Description

Versions of ascii-art before 1.4.4 are vulnerable to command injection. This is exploitable when user input is passed into the argument of the ascii-art preview command.

Recommendation

Update the ascii-art package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
ascii-art
Anything's wrong? Let us know Last updated on January 09, 2023

This issue is available in SmartScanner Professional

See Pricing