CVE-2019-10800

MEDIUM

codecov-python < 2.0.16 - OS Command Injection via Gcov Arguments

Title source: llm
STIX 2.1

Description

This affects the package codecov before 2.0.16. The vulnerability occurs due to not sanitizing gcov arguments before being being provided to the popen method.

References (2)

Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://snyk.io/vuln/SNYK-PYTHON-CODECOV-552149

Scores

CVSS v3 6.5
EPSS 0.0096
EPSS Percentile 56.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-88
Status published
Products (2)
codecov/codecov-python < 2.0.16
pypi/codecov 0 - 2.0.16PyPI
Published Jul 13, 2022
Tracked Since Feb 18, 2026