Arbitrary Argument Injection Affecting @grackle-ai/runtime-sdk package, versions <0.133.0


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Arbitrary Argument Injection vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JS-GRACKLEAIRUNTIMESDK-17817938
  • published5 Jul 2026
  • disclosed2 Jul 2026
  • creditUnknown

Introduced: 2 Jul 2026

CVE NOT AVAILABLE CWE-78  (opens in a new tab)
CWE-88  (opens in a new tab)

How to fix?

Upgrade @grackle-ai/runtime-sdk to version 0.133.0 or higher.

Overview

@grackle-ai/runtime-sdk is a Grackle runtime SDK — interfaces, base classes, shared utilities, and runtime installer

Affected versions of this package are vulnerable to Arbitrary Argument Injection via unsanitized input to the branch parameter in the SpawnSession process. An attacker can execute arbitrary commands as the application user on provisioned environments by supplying crafted branch names that are concatenated into a shell command without proper validation.

CVSS Base Scores

version 4.0
version 3.1