{"id":"GHSA-4859-gpc7-4j66","aliases":[],"url":"https://o3.security/vulnerability/GHSA-4859-gpc7-4j66","summary":"Command Injection in dot","details":"All versions of dot are vulnerable to Command Injection. The template compilation may execute arbitrary commands if an attacker can inject code in the template or if a Prototype Pollution-like vulnerability can be exploited to alter an Object's prototype.","published":"2019-06-05T21:24:29Z","modified":"2021-08-04T20:55:57Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"dot","fixedVersion":null}],"fix":null,"references":[{"type":"WEB","url":"https://hackerone.com/reports/390929"},{"type":"WEB","url":"https://www.npmjs.com/advisories/798"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2021-08-04T20:55:57Z"}}