← Back to CVE List

CVE-2023-26107

Published: 2023-03-06T05:15Z
Last Modified: 2025-03-05T20:15Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
All versions of the package sketchsvg are vulnerable to Arbitrary Code Injection when invoking shell.exec without sanitization nor parametrization while concatenating the current directory as part of the command string. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt