Description
An issue was discovered in the crunch function in shenzhim aaptjs 1.3.1, allows attackers to execute arbitrary code via the filePath parameters.
Remediation
References
https://github.com/shenzhim/aaptjs/issues/2
Related Vulnerabilities
CVE-2022-35513 Vulnerability in npm package blink1control2
CVE-2020-8141 Vulnerability in maven package org.webjars.bowergithub.olado:dot
CVE-2022-41654 Vulnerability in npm package ghost
CVE-2022-25857 Vulnerability in maven package org.yaml:snakeyaml
CVE-2021-3859 Vulnerability in maven package io.undertow:undertow-core