jsii-diff is vulnerable to Command Injection
78
High Risk
jsii-diff accepts npm: package specifiers and interpolates the package string into shell-executed npm install and npm show commands. A crafted package specifier can inject shell metacharacters and execute additional commands when jsii-diff downloads a package for comparison. This can compromise developer machines or CI jobs that run jsii-diff on untrusted package input. The fix validates the npm package specifier against an allowlist before invoking shell-backed npm commands.
You are affected if you are using a version that falls within the vulnerable range.
jsii-diff is vulnerable to Command Injection in versions 0.9.0 - 1.130.0.
Upgrade the jsii-diff library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant