@salesforce/cli@2.103.2 vulnerabilities

The Salesforce CLI

  • latest version

    2.107.6

  • latest non vulnerable version

  • first published

    4 years ago

  • latest version published

    10 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the @salesforce/cli package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Uncontrolled Search Path Element

    @salesforce/cli is a The Salesforce CLI

    Affected versions of this package are vulnerable to Uncontrolled Search Path Element via the Replace Trusted Executable feature. An attacker can execute arbitrary code by placing a malicious executable in a directory that is searched before the intended trusted executable.

    Note:

    This vulnerability affects only those customers who downloaded the software from an untrusted source, rather than directly from the official Salesforce site. Untrusted downloads may contain a malicious file in the local directory, which could be executed instead of the legitimate files in the specified file path.

    How to fix Uncontrolled Search Path Element?

    Upgrade @salesforce/cli to version 2.106.6 or higher.

    <2.106.6