CVE-2019-10800

MEDIUM

codecov <2.0.16 - Code Injection

Title source: llm

Description

This affects the package codecov before 2.0.16. The vulnerability occurs due to not sanitizing gcov arguments before being being provided to the popen method.

Scores

CVSS v3 6.5
EPSS 0.0032
EPSS Percentile 54.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-88
Status published

Affected Products (2)

codecov/codecov-python < 2.0.16
pypi/codecov < 2.0.16PyPI

Timeline

Published Jul 13, 2022
Tracked Since Feb 18, 2026