jakejs / jake

JavaScript build tool, similar to Make or Rake. Built to work with Node.js.
http://jakejs.com
Apache License 2.0
1.96k stars 190 forks source link

Security issue #389

Closed EffectRenan closed 3 years ago

EffectRenan commented 3 years ago

Hello, I have been researching some vulnerabilities on this package and I found a Command Injection vulnerability. Could you check this vulnerability?

The report contains the vulnerability description and a possible solution: https://github.com/418sec/jake/pull/2

Thanks for your attention.