{"id":"GHSA-jcgr-9698-82jx","aliases":[],"url":"https://o3.security/vulnerability/GHSA-jcgr-9698-82jx","summary":"Improper Neutralization of Special Elements used in a Command ('Command Injection') in @floffah/build","details":"### Impact\nIf you are using the esbuild target or command you are at risk of code/option injection. Attackers can use the command line option to maliciously change your settings in order to damage your project.\n\n### Patches\nThe problem has been patched in v1.0.0 as it uses a proper method to pass configs to esbuild/estrella.\n\n### Workarounds\nThere is no work around. You should update asap.\n\n### Notes\nThis notice is mainly just to make sure people update to the latest version. This isn't that bad, but should encourage you to update.","published":"2021-05-28T15:53:40Z","modified":"2021-05-27T21:05:29Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"@floffah/build","fixedVersion":"1.0.0"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/Floffah/build/security/advisories/GHSA-jcgr-9698-82jx"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2021-05-27T21:05:29Z"}}