Vulnerabilities > Toolkit Project

DATE CVE VULNERABILITY TITLE RISK
2020-10-01 CVE-2020-15228 Command Injection vulnerability in Toolkit Project Toolkit
In the `@actions/core` npm module before version 1.2.6,`addPath` and `exportVariable` functions communicate with the Actions Runner over stdout by generating a string in a specific format.
network
low complexity
toolkit-project CWE-77
5.0