DirectorySecurity Advisories
Sign In
Security Advisories

CGA-mqvq-9r52-63qw

Published

Last updated

https://images.chainguard.dev/security/CGA-mqvq-9r52-63qw
Package

snyk-cli

Latest Update
Fixed
Fixed Version

1.1294.0-r0

Aliases
  • CVE-2024-48963
  • GHSA-69f9-h8f9-7vjf

Severity

7.5

High

CVSS V3

Summary

OS Command Injection in Snyk php plugin

Description

The Snyk php plugin is vulnerable to Code Injection when scanning an untrusted PHP project. The vulnerability can be triggered if Snyk test is run inside the untrusted project due to the improper handling of the current working directory name. Snyk recommends only scanning trusted projects.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images