CVE-2019-10800
MEDIUMcodecov <2.0.16 - Code Injection
Title source: llmDescription
This affects the package codecov before 2.0.16. The vulnerability occurs due to not sanitizing gcov arguments before being being provided to the popen method.
Scores
CVSS v3
6.5
EPSS
0.0032
EPSS Percentile
54.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-88
Status
published
Affected Products (2)
codecov/codecov-python
< 2.0.16
pypi/codecov
< 2.0.16PyPI
Timeline
Published
Jul 13, 2022
Tracked Since
Feb 18, 2026