{"id":"GHSA-3988-h75v-hwf6","aliases":[],"url":"https://o3.security/vulnerability/GHSA-3988-h75v-hwf6","summary":"Arbitrary shell execution","details":"A properly crafted filename would allow for arbitrary code execution when using the --filter=gitmodified command line option","published":"2022-03-26T00:06:45Z","modified":"2024-12-05T05:40:06.764087Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"squizlabs/php_codesniffer","fixedVersion":"3.0.1"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/squizlabs/php_codesniffer/2017-05-18.yaml"},{"type":"PACKAGE","url":"https://github.com/squizlabs/PHP_CodeSniffer"},{"type":"WEB","url":"https://github.com/squizlabs/PHP_CodeSniffer/releases/tag/3.0.1"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-05T05:40:06.764087Z"}}