CVE-2019-10800

MEDIUM

codecov-python < 2.0.16 - OS Command Injection via Gcov Arguments

Title source: llm
STIX 2.1

Description

This affects the package codecov before 2.0.16. The vulnerability occurs due to not sanitizing gcov arguments before being being provided to the popen method.

References (2)

Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://snyk.io/vuln/SNYK-PYTHON-CODECOV-552149

Scores

CVSS v3 6.5
EPSS 0.0115
EPSS Percentile 63.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-88
Status published
Products (2)
codecov/codecov-python < 2.0.16
pypi/codecov 0 - 2.0.16PyPI
Published Jul 13, 2022
Tracked Since Feb 18, 2026