Command Injection in jison
High severity
GitHub Reviewed
Published
Oct 8, 2020
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Withdrawn
This advisory was withdrawn on Oct 19, 2020
Description
Reviewed
Oct 8, 2020
Published to the GitHub Advisory Database
Oct 8, 2020
Withdrawn
Oct 19, 2020
Last updated
Jan 9, 2023
Withdrawn: This vulnerability is not present in the released npm package. Rather the vulnerable code is
part of the repo, but not part of the package. See linked hackerone report for more details.
Insufficient input validation in npm package
jison
<= 0.4.18 may lead to OS command injection attacks.References