Vulnerabilities/

Command Injection in dot

Severity:
Medium

Description

All versions of dot are vulnerable to Command Injection. The template compilation may execute arbitrary commands if an attacker can inject code in the template or if a Prototype Pollution-like vulnerability can be exploited to alter an Object’s prototype.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
dot
Anything's wrong? Let us know Last updated on January 09, 2023

This issue is available in SmartScanner Professional

See Pricing