{"id":"GHSA-26hp-cgjj-m2j3","aliases":[],"url":"https://o3.security/vulnerability/GHSA-26hp-cgjj-m2j3","summary":"fuel/core ImageMagick driver does not escape all shell arguments.","details":"This vulnerability may cause OS commands to be executed when you pass unvalidated image filenames containing specially crafted strings to the ImageMagick driver.","published":"2024-05-15T21:44:46Z","modified":"2024-11-29T05:41:52.002545Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"fuel/core","fixedVersion":"1.8.0.4"}],"fix":{"url":"https://github.com/fuel/core/commit/95c134e9e087f3c4523fe6cd86ed4e9e1e7af91c","label":"fuel/core@95c134e"},"references":[{"type":"WEB","url":"https://github.com/fuel/core/commit/95c134e9e087f3c4523fe6cd86ed4e9e1e7af91c"},{"type":"WEB","url":"https://fuelphp.com/security-advisories"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/fuel/core/2016-06-29-1.yaml"},{"type":"PACKAGE","url":"https://github.com/fuel/core"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-11-29T05:41:52.002545Z"}}