Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:35571
HistoryMay 17, 2022 - 9:12 a.m.

Command Injection

2022-05-1709:12:26
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
18

0.002 Low

EPSS

Percentile

53.0%

workspace-tools is vulnerable to command Injection. The vulnerability exists in fetchRemoteBranch function in git.ts due to lack of sanitization in flagging inputs which allows a malicious attacker to inject and execute arbitrary code.

0.002 Low

EPSS

Percentile

53.0%

Related for VERACODE:35571