squizlabs/php_codesniffer is vulnerable to Command Injection
73
High Risk
The Gitblame, Hgblame, and Svnblame report generators build OS commands from scanned file names without neutralizing shell metacharacters. A file whose name contains shell metacharacters can cause attacker-controlled commands to run when those blame reports process untrusted trees, such as in CI that scans pull requests or on a developer machine reviewing third-party code. Default and other non-blame reports are not affected. The fix escapes or otherwise sanitizes file names before they are passed to the shell for blame report generation.
You are affected if you are using a version that falls within the vulnerable range and run PHP_CodeSniffer with the Gitblame, Hgblame, or Svnblame report formats over untrusted files.
squizlabs/php_codesniffer is vulnerable to Command Injection in versions 1.0.0 - 3.13.5 and 4.0.0 - 4.0.1.
Upgrade the squizlabs/php_codesniffer library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant