Synk Sweater Comb 3.8.8 之前的版本存在命令注入漏洞。攻击者若能控制 配置文件,即可通过向 分支名字段中注入恶意输入,从而执行任意的操作系统命令。 中的 函数未对分支名进行清洗,直接将其通过未转义的反引号模板字符串传入 ,导致在对仓库执行 lint 命令时,可被利用以实现任意命令执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| snyk | sweater-comb | < 3.8.8 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| snyk | sweater-comb | 0 ~ 3.8.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet