reg-keygen-git-hash-plugin is a reg-suit plugin to detect the snapshot key to be compare with using Git commit hash. reg-keygen-git-hash-plugin through and including 0.10.15 allow remote attackers to execute of arbitrary commands. Upgrade to version 0.10.16 or later to resolve this issue.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| reg-keygen-git-hash-plugin(npm) | 0 | 0.10.16 | N/A |
CVSS Metrics