VYPR
Vendor

Install Package Project

Products
1
CVEs
2
Across products
2
Status
Private

Products

1

Recent CVEs

2
  • CVE-2020-7629CriApr 2, 2020
    risk 0.64cvss 9.8epss 0.04

    install-package through 0.4.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the options argument.

  • CVE-2020-7628CriApr 2, 2020
    risk 0.64cvss 9.8epss 0.02

    umount through 1.1.6 is vulnerable to Command Injection. The argument device can be controlled by users without any sanitization.