Vulnerabilities (CVE)

Filtered by vendor Pull It Project Subscribe
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-25083 1 Pull It Project 1 Pull It 2024-02-28 N/A 9.8 CRITICAL
The pullit package before 1.4.0 for Node.js allows OS Command Injection because eval is used on an attacker-supplied Git branch name.