NietThijmen ShoppingCart: Command injection in the connect function
High severity
GitHub Reviewed
Published
Apr 15, 2026
to the GitHub Advisory Database
•
Updated Apr 16, 2026
Package
Affected versions
<= 0.0.0-20241101155353-3dd137080276
Patched versions
None
Description
Published by the National Vulnerability Database
Apr 15, 2026
Published to the GitHub Advisory Database
Apr 15, 2026
Reviewed
Apr 16, 2026
Last updated
Apr 16, 2026
Command injection in the connect function in NietThijmen ShoppingCart 0.0.2 allows an attacker to execute arbitrary shell commands and achieve remote code execution via injection of malicious payloads into the Port field
References