Security Advisory

CVE-2022-21186

9.8
CRITICAL

Vulnerability Description

The package @acrontum/filesystem-template before 0.0.2 are vulnerable to Arbitrary Command Injection due to the fetchRepo API missing sanitization of the href field of external input.
Published Date August 5, 2022
Official Source NIST NVD Advisory