VYPR

Vcs

by Vcs Project

CVEs (1)

  • CVE-2022-21235HigApr 1, 2022
    risk 0.46cvss 8.1epss 0.02

    The package github.com/masterminds/vcs before 1.13.3 are vulnerable to Command Injection via argument injection. When hg is executed, argument strings are passed to hg in a way that additional flags can be set. The additional flags can be used to perform a command injection.