All versions of the package sketchsvg are vulnerable to Arbitrary Code Injection when invoking shell.exec without sanitization nor parametrization while concatenating the current directory as part of the command string.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: snyk
Published: 2023-03-06T05:00:04.316Z
Updated: 2024-08-02T11:39:06.558Z
Reserved: 2023-02-20T10:28:48.921Z
Link: CVE-2023-26107
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-03-06T05:15:12.470
Modified: 2024-11-21T07:50:47.367
Link: CVE-2023-26107
Redhat
No data.