Snyk has a proof-of-concept or detailed explanation of how to exploit this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade extra-asciinema
to version 1.0.23 or higher.
extra-asciinema is an asciinema is a terminal screen recorder.
Affected versions of this package are vulnerable to Command Injection via insecure command formatting. The issue occurs because a user input parameter is used inside a command that is executed without any check.