@ai-hero/sandcastle is vulnerable to Command Injection
85
High Risk
Affected versions allow attacker-controlled promptArgs to be injected into prompts and mistakenly executed as shell commands, leading to possible command or remote shell execution.
You are affected if you are using a version that falls within the vulnerable range.
@ai-hero/sandcastle is vulnerable to Command Injection in versions 0.2.0 - 0.5.3.
Upgrade the @ai-hero/sandcastle library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant