VYPR

npm package

snyk-go-plugin

pkg:npm/snyk-go-plugin

Vulnerabilities (1)

  • CVE-2022-40764Oct 3, 2022
    affected < 1.19.1fixed 1.19.1

    Snyk CLI before 1.996.0 allows arbitrary command execution, affecting Snyk IDE plugins and the snyk npm package. Exploitation could follow from the common practice of viewing untrusted files in the Visual Studio Code editor, for example. The original demonstration was with shell