react-on-rails is vulnerable to Improper Input Validation
80
High Risk
Affected versions of this package are vulnerable to improper input validation, specifically in the generator package installation commands, where unsafe string interpolation allowed command injection. An attacker could exploit this by crafting malicious inputs, such as specially crafted package names or arguments, that bypass validation and execute arbitrary commands on the host system, potentially leading to unauthorized access or system compromise.
You are affected if you are using a version that falls within the vulnerable range.
react-on-rails is vulnerable to Improper Input Validation in versions 16.0.0 - 16.0.1.
Upgrade the react-on-rails library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant