GMS-2020-2: Uncontrolled Search Path Element
Attackers could trick execa into executing arbitrary binaries. This behaviour is caused by the setting preferLocal=true
which makes execa search for locally installed binaries and executes them. This vulnerability is usually only exploitable when using execa on a client-side LOCAL application.
References
Detect and mitigate GMS-2020-2 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →