You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository has been archived by the owner on Feb 18, 2022. It is now read-only.
Affected package: node-notifier
Ecosystem: NPM
Affected version range: < 8.0.1
Summary: OS Command Injection in node-notifier
Description: This affects the package node-notifier before 8.0.1. It allows an attacker to run arbitrary commands on Linux machines due to the options params not being sanitised when being passed an array.
identifiers: [{'type': 'GHSA', 'value': 'GHSA-5fw9-fq32-wv5p'}, {'type': 'CVE', 'value': 'CVE-2020-7789'}]
Fixed Version: 8.0.1
Created Date = January 25, 2022
---
The text was updated successfully, but these errors were encountered:
The text was updated successfully, but these errors were encountered: