{"id":"GHSA-gc94-6w89-hpqr","aliases":[],"url":"https://o3.security/vulnerability/GHSA-gc94-6w89-hpqr","summary":"Command Injection in fs-path","details":"All versions of `fs-path` are vulnerable to command injection is unsanitized user input is passed in.\n\n\n## Recommendation\n\nNo fix is currently available for this vulnerability. It is our recommendation to not install or use this module until a fix is available.","published":"2019-06-12T16:37:07Z","modified":"2021-09-16T20:59:56Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"fs-path","fixedVersion":"0.0.25"}],"fix":{"url":"https://github.com/pillys/fs-path/pull/5","label":"pillys/fs-path#5"},"references":[{"type":"WEB","url":"https://github.com/pillys/fs-path/pull/5"},{"type":"WEB","url":"https://hackerone.com/reports/324491"},{"type":"PACKAGE","url":"https://github.com/pillys/fs-path"},{"type":"WEB","url":"https://www.npmjs.com/advisories/661"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2021-09-16T20:59:56Z"}}