High severity7.4NVD Advisory· Published Dec 14, 2022· Updated Jun 17, 2026
CVE-2022-24377
CVE-2022-24377
Description
The package cycle-import-check before 1.3.2 are vulnerable to Command Injection via the writeFileToTmpDirAndOpenIt function due to improper user-input sanitization.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
cycle-import-checknpm | < 1.3.2 | 1.3.2 |
Affected products
3- cpe:2.3:a:cycle-import-check_project:cycle-import-check:*:*:*:*:*:*:*:*Range: <1.3.2
- cycle-import-check/cycle-import-checkdescription
Patches
Vulnerability mechanics
References
4- github.com/Soontao/cycle-import-check/commit/1ca97b59df7e9c704471fcb4cf042ce76d7c9890nvdPatchThird Party AdvisoryWEB
- security.snyk.io/vuln/SNYK-JS-CYCLEIMPORTCHECK-3157955nvdExploitPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-995x-33wq-8gc9ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-24377ghsaADVISORY
News mentions
0No linked articles in our index yet.