Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
naholyr github-todos 3.1.0 is vulnerable to command injection. The range argument for the _hook subcommand is concatenated without any validation, and is directly used by the exec function.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Github-Todos 操作系统命令注入漏洞
Vulnerability Description
Github-Todos是法国Nicolas Chambrier个人开发者的用于将 Todo 转换为 Github 问题。 naholyr github-todos 3.1.0 存在安全漏洞,该漏洞源于 _hook 子命令的 range 参数在没有任何验证的情况下连接起来,直接由 exec 函数使用。
CVSS Information
N/A
Vulnerability Type
N/A