0.14.0
3 months ago
9 days ago
Known vulnerabilities in the safeinstall-cli package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
safeinstall-cli is a Local-first CLI that blocks risky npm, pnpm, and bun installs before they run. Open source. Affected versions of this package are vulnerable to Protection Mechanism Failure through improper shell command parsing in the agent guard. An attacker can execute arbitrary commands with the permissions of the developer account by crafting shell commands that bypass policy evaluation and enforcement, potentially compromising local source code, credentials, and development resources. This is only exploitable if a coding agent acts on attacker-influenced instructions and issues the crafted shell command. How to fix Protection Mechanism Failure? Upgrade | <0.10.2 |