#glob-npm

[ follow ]
Information security
fromTheregister
3 hours ago

Weaponized file name flaw allows RCE through glob

A shell-invocation flaw in glob's CLI -c option enables remote code execution on POSIX systems when processing attacker-controlled filenames; update affected glob versions immediately.
[ Load more ]