GHSA-wpvh-7c2r-23rh
GitHub Security Advisory
⚠ Unreviewed
MODERATE
Has CVE
Advisory Details
A low privileged remote attacker can use a command injection vulnerability in the API which performs
remote code execution as the user-app user due to improper input validation. The confidentiality is partly affected.
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: September 12, 2025 6:34 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.