VYPR

npm package

limdu

pkg:npm/limdu

Vulnerabilities (1)

  • CVE-2020-4066LowJun 22, 2020
    affected < 0.9.5fixed 0.9.5

    In Limdu before 0.95, the trainBatch function has a command injection vulnerability. Clients of the Limdu library are unlikely to be aware of this, so they might unwittingly write code that contains a vulnerability. This has been patched in 0.95.