⚠ Withdrawn by GitHub Security Advisories

Withdrawn: June 4, 2024

GHSA-6hr9-4692-fch9CriticalCVSS 9.8

Withdrawn Advisory: OS Command Injection in effect

Published
February 10, 2022
Last Modified
August 21, 2026

🔗 CVE IDs covered (1)

📋 Description

Withdrawn Advisory

This advisory has been withdrawn because the npm package effect, for which alerts were issued, does not correspond with https://github.com/Javascipt/effect, the repository with the vulnerable code. https://github.com/Javascipt/effect is not in any supported ecosystem.

Additionally, the CVE Numbering Authority that issued the CVE for CVE-2020-7624 has updated their advisory stating that "This was deemed not a vulnerability."

Original Description

effect through 1.0.4 is vulnerable to Command Injection. It allows execution of arbitrary command via the options argument.

🎯 Affected products1

  • npm/effect:<= 1.0.4

🔗 References (4)