{"id":"GHSA-3988-h75v-hwf6","summary":"Arbitrary shell execution","details":"A properly crafted filename would allow for arbitrary code execution when using the --filter=gitmodified command line option","modified":"2024-12-05T05:40:06.764087Z","published":"2022-03-26T00:06:45Z","database_specific":{"nvd_published_at":null,"cwe_ids":[],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2022-03-26T00:06:45Z"},"references":[{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/squizlabs/php_codesniffer/2017-05-18.yaml"},{"type":"PACKAGE","url":"https://github.com/squizlabs/PHP_CodeSniffer"},{"type":"WEB","url":"https://github.com/squizlabs/PHP_CodeSniffer/releases/tag/3.0.1"}],"affected":[{"package":{"name":"squizlabs/php_codesniffer","ecosystem":"Packagist","purl":"pkg:composer/squizlabs/php_codesniffer"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0.0"},{"fixed":"3.0.1"}]}],"versions":["3.0.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-3988-h75v-hwf6/GHSA-3988-h75v-hwf6.json"}}],"schema_version":"1.9.0"}