A vulnerability was found in
Ardatan graphql-tools up to 6.2.5. It has been rated as critical. Affected by this issue is the function
exec/execSync
of the file
packages/loaders/git/src/load-git.ts. Upgrading to version 6.2.6 eliminates this vulnerability. The upgrade is hosted for download at
github.com. Applying a patch is able to eliminate this problem. The bugfix is ready for download at
github.com. The best possible mitigation is suggested to be upgrading to the latest version.
Lien vers l'article source