falkTX / Cadence

Collection of tools useful for audio production
GNU General Public License v2.0
368 stars 80 forks source link

🚨 Potential Command Injection - Generic (CWE-77) #318

Closed huntr-helper closed 3 years ago

huntr-helper commented 3 years ago

👋 Hello, @falkTX - a potential medium severity Command Injection - Generic (CWE-77) vulnerability in your repository has been disclosed to us.

Next Steps

1️⃣ Visit https://huntr.dev/bounties/1-other-falkTX/Cadence for more advisory information.

2️⃣ Sign-up to validate or speak to the researcher for more assistance.

3️⃣ Propose a patch or outsource it to our community - whoever fixes it gets paid.

✏️ NOTE: If we don't hear from you in 14 days, we will proactively source a fix for this vulnerability (and open a PR) to ensure community safety.


Confused or need more help?


This issue was automatically generated by huntr.dev - a bug bounty board for securing open source code.

falkTX commented 3 years ago

The changes here make no sense. If os.system is broken, please fix that instead.

Also :

* Join us on our **[Discord](https://huntr.dev/discord)** and a member of our team will be happy to help!

Please do not promote privacy-invasive services here, thank you very much.