High severity8.1NVD Advisory· Published Jun 8, 2022· Updated Jun 17, 2026
CVE-2022-24065
CVE-2022-24065
Description
The package cookiecutter before 2.1.1 are vulnerable to Command Injection via hg argument injection. When calling the cookiecutter function from Python code with the checkout parameter, it is passed to the hg checkout command in a way that additional flags can be set. The additional flags can be used to perform a command injection.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
cookiecutterPyPI | < 2.1.1 | 2.1.1 |
Affected products
2- cookiecutter/cookiecutterdescription
Patches
Vulnerability mechanics
References
10- github.com/cookiecutter/cookiecutter/commit/fdffddb31fd2b46344dfa317531ff155e7999f77nvdPatchThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-PYTHON-COOKIECUTTER-2414281nvdExploitPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-f4q6-9qm4-h8j4ghsaADVISORY
- github.com/cookiecutter/cookiecutter/releases/tag/2.1.1nvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-24065ghsaADVISORY
- github.com/pypa/advisory-database/tree/main/vulns/cookiecutter/PYSEC-2022-204.yamlghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/G5TXC4JYTNGOUFMCXPZ6QKWEZN3URTAKghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/HQKWT7SGFDCUPPLDIELTN7FVTHWDL5YKghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/G5TXC4JYTNGOUFMCXPZ6QKWEZN3URTAK/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HQKWT7SGFDCUPPLDIELTN7FVTHWDL5YK/nvd
News mentions
0No linked articles in our index yet.