{"id":"GHSA-26hp-cgjj-m2j3","summary":"fuel/core ImageMagick driver does not escape all shell arguments.","details":"This vulnerability may cause OS commands to be executed when you pass unvalidated image filenames containing specially crafted strings to the ImageMagick driver.","modified":"2024-11-29T05:41:52.002545Z","published":"2024-05-15T21:44:46Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-05-15T21:44:46Z","nvd_published_at":null,"cwe_ids":["CWE-78"]},"references":[{"type":"WEB","url":"https://github.com/fuel/core/commit/95c134e9e087f3c4523fe6cd86ed4e9e1e7af91c"},{"type":"WEB","url":"https://fuelphp.com/security-advisories"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/fuel/core/2016-06-29-1.yaml"},{"type":"PACKAGE","url":"https://github.com/fuel/core"}],"affected":[{"package":{"name":"fuel/core","ecosystem":"Packagist","purl":"pkg:composer/fuel/core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.8.0.4"}]}],"versions":["1.8.0","1.8.0.1","1.8.0.2","1.8.0.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-26hp-cgjj-m2j3/GHSA-26hp-cgjj-m2j3.json"}}],"schema_version":"1.9.0"}