QID 983861
QID 983861: Nodejs (npm) Security Update for mversion (GHSA-qjg4-w4c6-f6c6)
Security update has been released for mversion to fix the vulnerability. Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
This issue may lead to remote code execution if a client of the library calls the vulnerable method with untrusted input.
Solution
Patched by version 2.0.0. Previous releases are deprecated in npm.Workaround:
Make sure to escape git commit messages when using the commitMessage option for the update function.
Make sure to escape git commit messages when using the commitMessage option for the update function.
Vendor References
- GHSA-qjg4-w4c6-f6c6 -
github.com/advisories/GHSA-qjg4-w4c6-f6c6
CVEs related to QID 983861
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-qjg4-w4c6-f6c6 | mversion |
|