Volo.Abp.Cli is vulnerable to OS Command Injection
42
Medium Risk
Affected versions of this package allow ABP CLI to execute shell commands defined in a project’s package.json, which could let a malicious project run arbitrary commands in a developer’s environment during normal CLI usage. Although ABP-generated projects are not expected to contain such entries, an attacker could exploit this by publishing or sharing a crafted ABP project that appears legitimate but includes a malicious command, leading to local code execution when the project is processed.
You are affected if you are using a version that falls within the vulnerable range.
Volo.Abp.Cli is vulnerable to OS Command Injection in versions 5.1.0 - 10.2.0.
Upgrade the Volo.Abp.Cli library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant