Vulnerability Details CVE-2022-25855
All versions of the package create-choo-app3 are vulnerable to Command Injection via the devInstall function due to improper user-input sanitization.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 47.8%
CVSS Severity
CVSS v3 Score 7.4
Products affected by CVE-2022-25855
-
cpe:2.3:a:create-choo-app3_project:create-choo-app3:-