jolicode/jolinotif is vulnerable to Code Injection
75
High Risk
PowerShellDriver inserts the notification title, body, and icon into single quoted strings inside a generated PowerShell script, and only escapes the ASCII apostrophe. A notification containing a Unicode quotation mark such as U+2018 or U+2019 breaks out of the string and runs arbitrary PowerShell commands with the privileges of the process sending the notification. This affects applications on Windows or WSL that use the PowerShell driver and send notifications whose title, body, or icon includes untrusted data. The fix embeds notification values as Base64 and decodes them inside PowerShell, so the content can no longer run as script code.
You are affected if you are using a version that falls within the vulnerable range and you run on Windows or WSL using the PowerShell driver with notification titles, bodies, or icons that include untrusted data.
jolicode/jolinotif is vulnerable to Code Injection in versions 3.2.0 - 3.4.0.
Upgrade the jolicode/jolinotif library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.