Vulnerabilities/

Command Injection in create-choo-electron

Severity:
High

Description

All versions of the package create-choo-electron are vulnerable to Command Injection via the devInstall function due to improper user-input sanitization.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
create-choo-electron
Anything's wrong? Let us know Last updated on April 01, 2025

This issue is available in SmartScanner Professional

See Pricing