← Back

Graphql Tools

graphql-tools

Vendor: The Guild • 1 CVE

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1The Guild
1Graphql Tools
Nov 21, 2024
Jan 20, 2021
N/A· v4
8.8 HIGH· v3
7.5 HIGH· v2
This affects the package @graphql-tools/git-loader before 6.2.6. The use of exec and execSync in packages/loaders/git/src/load-git.ts allows arbitrary command injection.