codeceptjs@3.7.5-beta.17 vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the codeceptjs package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • C
Arbitrary Command Injection

codeceptjs is a Supercharged End 2 End Testing Framework for NodeJS

Affected versions of this package are vulnerable to Arbitrary Command Injection via the emptyFolder function. An attacker can execute arbitrary system commands by supplying crafted input to the directoryPath parameter.

How to fix Arbitrary Command Injection?

Upgrade codeceptjs to version 3.7.5 or higher.

<3.7.5