Lucene search

K
osvGoogleOSV:GHSA-FRQG-7G38-6GCF
HistoryOct 05, 2021 - 8:23 p.m.

Improper escaping of command arguments on Windows leading to command injection

2021-10-0520:23:18
Google
osv.dev
10

EPSS

0.003

Percentile

68.2%

Impact

Windows users running Composer to install untrusted dependencies are affected and should definitely upgrade for safety. Other OSs and WSL are not affected.

Patches

1.10.23 and 2.1.9 fix the issue

Workarounds

None