Potential Command Injection in hubot-scripts
Critical severity
GitHub Reviewed
Published
Aug 31, 2020
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Reviewed
Aug 31, 2020
Published to the GitHub Advisory Database
Aug 31, 2020
Last updated
Jan 9, 2023
Versions 2.4.3 and earlier of hubot-scripts are vulnerable to a command injection vulnerablity in the
hubot-scripts/package/src/scripts/email.coffee
module.Mitigating Factors
The email script is not enabled by default, it has to be manually added to hubot's list of loaded scripts.
Recommendation
Update hubot-scripts to version 2.4.4 or later.
References