Snyk has a published code exploit for this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsThere is no fix version for buttle
.
buttle is a Simple static file (+ markdown) server.
Affected versions of this package are vulnerable to Arbitrary Command Injection. When buttle
is run with --php-bin
option (to handle PHP), the PHP filename is not sanitized and allows to inject shell commands.