CVE-2022-24377

HIGH

cycle-import-check <1.3.2 - Command Injection

Title source: llm
STIX 2.1

Description

The package cycle-import-check before 1.3.2 are vulnerable to Command Injection via the writeFileToTmpDirAndOpenIt function due to improper user-input sanitization.

Scores

CVSS v3 7.4
EPSS 0.0137
EPSS Percentile 80.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (2)
cycle-import-check_project/cycle-import-check < 1.3.2
npm/cycle-import-check 0 - 1.3.2npm
Published Dec 14, 2022
Tracked Since Feb 18, 2026