Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:35735
HistoryMay 27, 2022 - 6:31 a.m.

Arbitrary Command Injection

2022-05-2706:31:17
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13
sharp
vulnerability
arbitrary command injection
npm install
environment variable
build environment

EPSS

0

Percentile

5.2%

sharp is vulnerable to arbitrary command injection. An attacker is able to set the value of the PKG_CONFIG_PATH environment variable in a build environment which allows arbitrary command injection at npm install time.

EPSS

0

Percentile

5.2%

Related for VERACODE:35735