@parcel/install-package
Releases2
Frequency18 minutes
Last Release
Blazing fast, zero configuration web application bundler
CVE History
| CVE | Affected | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|---|
| all versions | 9.8 CRITICAL | 7.5 HIGH | ||
umount through 1.1.6 is vulnerable to Command Injection. The argument device can be controlled by users without any sanitization. | ||||
| <= 0.4.0 | 9.8 CRITICAL | 7.5 HIGH | ||
install-package through 0.4.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the options argument. | ||||