Description
All versions of dot are vulnerable to Command Injection. The template compilation may execute arbitrary commands if an attacker can inject code in the template or if a Prototype Pollution-like vulnerability can be exploited to alter an Object’s prototype.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 1.1.2
References
Related Issues
- Double spend in snarkjs - CVE-2023-33252
- SSRF & Credentials Leak - CVE-2023-49799
- Path Traversal in droppy - CVE-2020-7757
- Improper Control of Generation of Code in doT - CVE-2020-8141
- Tags:
- npm
- dot
Anything's wrong? Let us know Last updated on January 09, 2023