Description
Codecov npm module before 3.6.2 allows remote attackers to execute arbitrary commands via the "gcov-args" argument.
Remediation
References
https://snyk.io/vuln/SNYK-JS-CODECOV-543183
Related Vulnerabilities
CVE-2023-29199 Vulnerability in npm package vm2
CVE-2023-50481 Vulnerability in npm package blinksocks
CVE-2019-19703 Vulnerability in maven package io.ktor:ktor-client-core
CVE-2020-28494 Vulnerability in npm package total.js
CVE-2020-36180 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind