Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We鈥檒l occasionally send you account related emails.

Already on GitHub? Sign in to your account - Command Injection Fix #45

merged 4 commits into from
May 1, 2020


Copy link

@huntr-helper huntr-helper commented Apr 17, 2020 has fixed a security vulnerability (Command Injection) 馃敤. mufeedvh has been awarded $25 for fixing the vulnerability through the huntr bug bounty program 馃挼. Think you could fix a vulnerability like this? Get involved at!

Q | A
Version Affected | ALL
Bug Fix | YES
Original Pull Request | 418sec#1

Bounty URL:

index.js Outdated Show resolved Hide resolved
Fixing requested change to index value of version_cmds_exec.

Co-Authored-By: Kyle Farris <>
Copy link

@kylefarris - requested changes have been made! 馃嵃

Copy link

SaltwaterC commented Apr 30, 2020

@kylefarris out of curiosity, has this originated from the sockets branch since this issue has been patched in the old master of 0.8.2 like donkey's years ago?

Copy link

@SaltwaterC, it is quite odd. I rebased the sockets branch several times during development and then once more before merging into master. Maybe I didn't handle a conflict properly?

@kylefarris kylefarris merged commit 5f557c9 into kylefarris:master May 1, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
None yet
None yet

Successfully merging this pull request may close these issues.

None yet

5 participants