GHSA-3hq6-rmv7-39vhCriticalCVSS 9.8

Injection in op-browser

Published
February 10, 2022
Last Modified
July 6, 2026

🔗 CVE IDs covered (1)

📋 Description

op-browser through 1.0.9 is vulnerable to Command Injection. It allows execution of arbitrary commands via the url function.

🎯 Affected products1

  • npm/op-browser:<= 1.0.9

🔗 References (6)