2.0.1
12 years ago
5 years ago
Known vulnerabilities in the mversion package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
mversion is a cross packaging manager module version handler/bumper. Affected versions of this package are vulnerable to Command Injection. The issue occurs because PoC:
How to fix Command Injection? Upgrade | <2.0.1 |
mversion is a cross packaging manager module version handler/bumper. Affected versions of this package are vulnerable to Remote Code Execution (RCE). Shell git commit messages are not escaped. How to fix Remote Code Execution (RCE)? Upgrade | <2.0.0 |