zaach / jison

Bison in JavaScript.
http://jison.org
4.33k stars 448 forks source link

Security Notice & Bug Bounty - Command Injection - huntr.dev #391

Open huntr-helper opened 4 years ago

huntr-helper commented 4 years ago

Overview

jison is a package that provides an API for creating parsers in JavaScript.

Affected versions of this package are vulnerable to Command Injection. Arbitrary OS shell command execution is possible through a crafted command-line argument.

Bug Bounty

We have opened up a bounty for this issue on our bug bounty platform. Want to solve this vulnerability and get rewarded 💰? Go to https://huntr.dev/

We will submit a pull request directly to your repository with the fix as soon as possible. Want to learn more? Go to https://github.com/418sec/huntr 📚

Automatically generated by @huntr-helper...

huntr-helper commented 4 years ago

‎‍🛠️ A fix has been provided for this issue. Please reference: https://github.com/418sec/jison/pull/1

🔥 This fix has been provided through the https://huntr.dev/ bug bounty platform.