Command Injection Affecting codecov package, versions <3.7.1


0.0
medium

Snyk CVSS

    Attack Complexity Low
    Confidentiality High

    Threat Intelligence

    EPSS 1.6% (88th percentile)
Expand this section
NVD
9.3 critical

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-JS-CODECOV-585979
  • published 21 Jul 2020
  • disclosed 21 Jul 2020
  • credit Unknown

How to fix?

Upgrade codecov to version 3.7.1 or higher.

Overview

codecov is a npm package for uploading reports to Codecov.

Affected versions of this package are vulnerable to Command Injection via the upload method.

Note: This vulnerability exists due to an incomplete fix of CVE-2020-7597.