Loading HuntDB...

GHSA-6q8m-42qq-64r7

GitHub Security Advisory

Imperative CLI vulnerable to Command Injection

✓ GitHub Reviewed LOW Has CVE

Advisory Details

A vulnerability in Imperative framework which allows already-privileged local actors to execute arbitrary shell commands via plugin install/update commands, or maliciously formed environment variables. Impacts Zowe CLI.

Affected Packages

npm @zowe/imperative
Affected versions: 5.0.0 (fixed in 5.7.1)
npm @zowe/imperative
Affected versions: 0 (fixed in 4.18.10)

Related CVEs

Key Information

GHSA ID
GHSA-6q8m-42qq-64r7
Published
March 1, 2023 9:30 AM
Last Modified
March 2, 2023 5:16 PM
CVSS Score
2.5 /10
Primary Ecosystem
npm
Primary Package
@zowe/imperative
GitHub Reviewed
✓ Yes

Dataset

Last updated: November 25, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.