GHSA-pf8j-vhg8-xmc3CriticalCVSS 9.8
karma-mojo enables OS Command Injection
🔗 CVE IDs covered (1)
📋 Description
karma-mojo through 1.0.1 is vulnerable to Command Injection. It allows execution of arbitrary commands via the config argument.
🎯 Affected products1
- npm/karma-mojo:<= 1.0.1