Skip to content

Conversation

joernchen
Copy link

This PR will fix a command execution issue in the extension.

execa version 1.0 used in this extension searches the local path first when trying to find the php executable. By this a crafted project can override the php binary and execute arbitrary code.

@joernchen
Copy link
Author

@felixfbecker is there anything more I could do to help getting this merged and the command execution issue resolved?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant