Vulnerabilities/

create-choo-app3 is vulnerable to Command Injection via the devInstall function

Severity:
High

Description

All versions of the package create-choo-app3 are vulnerable to Command Injection via the devInstall function due to improper user-input sanitization.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
create-choo-app3
Anything's wrong? Let us know Last updated on March 25, 2025

This issue is available in SmartScanner Professional

See Pricing