Snyk CLI Vulnerable to Code Injection in Untrusted PHP Projects
CVE-2024-48963

9.8CRITICAL

Key Information:

Vendor

Snyk

Vendor
CVE Published:
23 October 2024

What is CVE-2024-48963?

The vulnerability identified in Snyk CLI versions before 1.1294.0 poses a significant security risk related to code injection during scans of untrusted PHP projects. This issue arises from the improper management of the current working directory name, which can be exploited if the Snyk test is executed within the context of a potentially malicious project. Snyk advises users to restrict scans to only trusted projects to mitigate this risk.

Affected Version(s)

Snyk Cli 0 < 1.1294.0

Snyk PHP Plugin 0 < 1.10.0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.