← Back to CVE List

CVE-2022-24065

Published: 2022-06-08T08:15Z
Last Modified: 2024-11-21T06:49Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The package cookiecutter before 2.1.1 are vulnerable to Command Injection via hg argument injection. When calling the cookiecutter function from Python code with the checkout parameter, it is passed to the hg checkout command in a way that additional flags can be set. The additional flags can be used to perform a command injection. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt