@qwen-code/qwen-code is vulnerable to Command Injection
55
Medium Risk
Affected versions of this package allow newline-separated command injection where only the first line is validated. An attacker can place a multi-line instruction containing a benign read-only command followed by a malicious one, bypassing safety checks because the parser did not treat \n/\r\n as command separators. As a result, validation approves the first command while subsequent arbitrary commands execute silently without user confirmation.
You are affected if you are using a version that falls within the vulnerable range. Requires user interaction / untrusted input in CLI context.
@qwen-code/qwen-code is vulnerable to Command Injection in versions 0.0.1 - 0.8.2.
Upgrade the @qwen-code/qwen-code library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant