← Back to browse · API

CVE-2022-21186

Severity
CRITICAL
CVSS
9.8
EPSS
0.24865
Risk score
47.9
CISA KEV
No
PoC
No
Published
2022-08-05
Modified
2024-09-16
First seen
2026-08-07
Aliases
EUVD-2022-6583, GHSA-M2FC-9H5M-29CM
Products
n/a:@acrontum/filesystem-template unspecified <0.0.2
Sources
euvd EUVD-2022-6583

Description

The package @acrontum/filesystem-template before 0.0.2 are vulnerable to Arbitrary Command Injection due to the fetchRepo API missing sanitization of the href field of external input.

References