VYPR
High severity7.4NVD Advisory· Published Dec 14, 2022· Updated Jun 17, 2026

CVE-2022-24377

CVE-2022-24377

Description

The package cycle-import-check before 1.3.2 are vulnerable to Command Injection via the writeFileToTmpDirAndOpenIt function due to improper user-input sanitization.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
cycle-import-checknpm
< 1.3.21.3.2

Affected products

3

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.