Intel

AIKIDO-2026-371295

jolicode/jolinotif is vulnerable to Code Injection

Code InjectionGHSA-c59g-hrf8-6q4c Published Yesterday

75

High Risk

This Affects:

PHPjolicode/jolinotif
3.2.0 - 3.4.0
Fixed in 3.4.1
Are you affected? Scan for Free

TL;DR

PowerShellDriver inserts the notification title, body, and icon into single quoted strings inside a generated PowerShell script, and only escapes the ASCII apostrophe. A notification containing a Unicode quotation mark such as U+2018 or U+2019 breaks out of the string and runs arbitrary PowerShell commands with the privileges of the process sending the notification. This affects applications on Windows or WSL that use the PowerShell driver and send notifications whose title, body, or icon includes untrusted data. The fix embeds notification values as Base64 and decodes them inside PowerShell, so the content can no longer run as script code.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you run on Windows or WSL using the PowerShell driver with notification titles, bodies, or icons that include untrusted data.

Background info

jolicode/jolinotif is vulnerable to Code Injection in versions 3.2.0 - 3.4.0.

How to fix this

Upgrade the jolicode/jolinotif library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform