{"id":"CVE-2020-4066","aliases":[],"url":"https://o3.security/vulnerability/CVE-2020-4066","summary":"Command Injection in Limdu","details":"### Impact\nThe `trainBatch` function has a command injection vulnerability. Clients of the Limdu library are unlikely to be aware of this, so they might unwittingly write code that contains a vulnerability.\n\n### Patches\nPatched in version 0.9.5.\n\n### Workarounds\nDo not use trainBatch with classifiers that rely on shell execution, such as SVM Perf, SVM Linear or Adaboost\n\n### References\nNo","published":"2020-06-22T15:24:06Z","modified":"2026-05-04T08:45:57.335613990Z","cvss":{"score":3.8,"severity":"LOW","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"limdu","fixedVersion":"0.9.5"}],"fix":{"url":"https://github.com/erelsgl/limdu/commit/03475a6a6bb253de6fad8f7f39cfb3504f11438d","label":"erelsgl/limdu@03475a6"},"references":[{"type":"WEB","url":"https://github.com/erelsgl/limdu/security/advisories/GHSA-77qv-gh6f-pgh4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-4066"},{"type":"WEB","url":"https://github.com/erelsgl/limdu/commit/03475a6a6bb253de6fad8f7f39cfb3504f11438d"},{"type":"PACKAGE","url":"https://github.com/erelsgl/limdu"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-05-04T08:45:57.335613990Z"}}