Skip to content

Code injection in nbgitpuller

Critical
minrk published GHSA-mq5p-2mcr-m52j Aug 25, 2021

Package

pip nbgitpuller (pip)

Affected versions

0.9.0 < 0.10.1

Patched versions

0.10.2

Description

Impact

Due to an unsanitized input, visiting maliciously crafted links could result in arbitrary code execution in the user environment.

Patches

0.10.2

Workarounds

None, other than upgrade to 0.10.2 or downgrade to 0.8.x.

For more information

If you have any questions or comments about this advisory:

Severity

Critical

CVE ID

CVE-2021-39160

Weaknesses