[thi.ng/egf] Potential arbitrary code execution of `#gpg`-tagged property values
- Severity:
- Medium
Description
Potential for arbitrary code execution in #gpg-tagged property values (only if decrypt: true option is enabled)
Recommendation
Update the @thi.ng/egf package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.4.0
- Patched version(s): 0.4.0
References
Related Issues
- Trix Editor Arbitrary Code Execution Vulnerability - CVE-2024-34341
- Arbitrary Code Execution in mathjs (GHSA-vx5c-87qx-cv6c) - CVE-2017-1001002
- Remote code execution in Eclipse Theia - CVE-2021-34435
- Joplin is vulnerable to arbitrary code execution - CVE-2022-35131
- Tags:
- npm
- @thi.ng/egf
Anything's wrong? Let us know Last updated on February 01, 2023