django-migration-linter is vulnerable to OS Command Injection
99
Critical Risk
If your 'git-commit-id' comes from a potentially untrusted source (e.g., an API), an attacker could manipulate it to execute shell commands, such as: ./manage.py lintmigrations --git-commit-id '; rm -rf dangerous', potentially running harmful code.
You are affected if you are using a version of this package = 5.0.0.
django-migration-linter is vulnerable to OS Command Injection in versions 0.0.1 - 5.0.0.
Upgrade the django-migration-linter library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant