Files
codeql/javascript/change-notes/2021-07-12-read-pkg.md
2021-07-12 23:43:15 +02:00

5 lines
187 B
Markdown

lgtm,codescanning
* The `cwd` option from the `read-pkg` library is recognized as a sink for `js/tainted-path`.
Affected packages are
[read-pkg](https://npmjs.com/package/read-pkg)