High severity7.5NVD Advisory· Published Oct 23, 2024· Updated Jun 17, 2026
CVE-2024-48964
CVE-2024-48964
Description
The package Snyk CLI before 1.1294.0 is vulnerable to Code Injection when scanning an untrusted Gradle project. The vulnerability can be triggered if Snyk test is run inside the untrusted project due to the improper handling of the current working directory name. Snyk recommends only scanning trusted projects.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
snyk-gradle-pluginnpm | < 4.5.0 | 4.5.0 |
Affected products
5- osv-coords3 versions
< 1.1294.0-r0+ 2 more
- (no CPE)range: < 1.1294.0-r0
- (no CPE)range: < 1.1294.0-r0
- (no CPE)range: < 4.5.0
- Range: 0
- Snyk/Snyk Gradle Pluginv5Range: 0
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.