Releases0
Stars5.25K
๐Ÿฆ :package: a package registry for anything, but mostly javascript ๐Ÿฆ ๐Ÿฆ ๐Ÿฆ

CVE History

CVEPublishedCVSS v3CVSS v2
โ€”5 MEDIUM

cli/lib/main.js in Entropic before 2019-06-13 does not reject / and \ in command names, which might allow a directory traversal attack in unusual situations.