Last 12 weeks · 10 commits
3 of 6 standards met
Summary Harden input handling in (flagged by semgrep). Vulnerability Description*: Detected calls to child_process from a function argument . This could lead to a command injection if the input is user controllable. Try to avoid calls to child_process, and if it is needed ensure user input is correctly sanitized or sandboxed. Threat Model Context This is a private Node.js application (not published to npm). Vulnerabilities affect this application's own runtime only. Changes Behavior Preservation The change is scoped to 1 file on the vulnerable path; it only tightens handling of untrusted input and leaves valid inputs unaffected. This patch removes an exploit primitive — a code pattern that, while not independently exploitable today, could be chained with other weaknesses by automated exploit-development tooling. Proactive removal of such primitives raises the bar against increasingly capable automated attack tools. Automated security fix by OrbisAI Security*
Repository: vitejs/launch-editor. Description: Open file in editor from Node.js. Stars: 721, Forks: 95. Primary language: JavaScript. Languages: JavaScript (100%). License: MIT. Open PRs: 10, open issues: 14. Last activity: 4d ago. Community health: 62%. Top contributors: haoqunjiang, sapphi-red, yyx990803, renovate[bot], TrySound, dependabot[bot], SamVerschueren, nrayburn-tech, kirisakow, dominikg and others.