rulesync is vulnerable to Improper Input Validation
45
Medium Risk
Affected versions of this package lack sufficient validation and sanitization when handling file paths, repository inputs, and remote fetch operations, allowing improper path handling, weak hostname validation, and unsafe API parameter usage. An attacker could exploit these weaknesses by supplying crafted repository URLs, malicious output paths, or manipulated file references to trigger path traversal, overwrite arbitrary files, bypass trusted domain checks, or force the system to fetch malicious or oversized files, potentially leading to unauthorized file access, data tampering, or denial of service.
You are affected if you are using a version that falls within the vulnerable range.
rulesync is vulnerable to Improper Input Validation in versions 0.1.0 - 6.4.0.
Upgrade the rulesync library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant