nono is vulnerable to Link Following
50
Medium Risk
@git:common-dir, @git:worktree, and @git:toplevel-parent resolve a .git file's gitdir: pointer with a plain file read and follow it with no check against the agent's capability set. An agent can plant gitdir: /protected/dir in a writable directory and get that path granted. The fix rejects a resolved gitdir or commondir target that is not already covered by the agent's capability set.
You are affected if you are using a version that falls within the vulnerable range and you use the @git:common-dir, @git:worktree, or @git:toplevel-parent dynamic providers.
nono is vulnerable to Link Following in versions 0.0.1 - 0.77.0.
Upgrade the nono library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.