bundle-name is vulnerable to Code Injection
42
Medium Risk
bundleName inserts the caller supplied bundle identifier directly into an AppleScript string passed to runAppleScript without validating it. A bundle identifier containing a double quote, backslash, or line break can escape the AppleScript string literal and inject additional statements, so untrusted input can run arbitrary AppleScript. The fix adds a type check and a bundleIdentifierPattern regex that rejects any identifier containing quotes, backslashes, or newlines before it reaches the AppleScript template.
You are affected if you are using a version that falls within the vulnerable range and you pass an untrusted bundle identifier into bundleName.
bundle-name is vulnerable to Code Injection in versions 0.1.0 - 4.1.0.
Upgrade the bundle-name library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.