PT-2021-16985 · Unknown · Eslint-Fixer

CVE-2021-26275

·

Published

2021-03-18

·

Updated

2024-08-03

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions eslint-fixer versions 0.1.5 and earlier
Description The issue allows command injection via shell metacharacters to the fix function. This affects products that are no longer supported by the maintainer. The ozum/eslint-fixer GitHub repository has been intentionally deleted.
Recommendations For versions 0.1.5 and earlier, as a temporary workaround, consider disabling the fix function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-26275
GHSA-45W5-PVR8-4RH5

Affected Products

Eslint-Fixer