lookatme@0.1.1 vulnerabilities

An interactive, command-line presentation tool

  • latest version

    2.5.5

  • latest non vulnerable version

  • first published

    5 years ago

  • latest version published

    2 years ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the lookatme package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Command Injection

    lookatme is an interactive, terminal-based markdown presenter.

    Affected versions of this package are vulnerable to Command Injection. The package automatically loaded the built-in terminal and file_loader extensions. Users that use lookatme to render untrusted markdown may have malicious shell commands automatically run on their system.

    How to fix Command Injection?

    Upgrade lookatme to version 2.3.0 or higher.

    [,2.3.0)