Skip to content

[Aikido] Fix security issue in open via minor version upgrade from 5.3.4 to 5.4.0 in src-tauri - #52

Merged
cst8t merged 1 commit into
v0.12.1-developfrom
fix/aikido-security-update-packages-133368473-kejp
Oct 4, 2026
Merged

cst8t merged 1 commit into
v0.12.1-developfrom
fix/aikido-security-update-packages-133368473-kejp

Conversation

@aikido-autofix

@aikido-autofix aikido-autofix Bot commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

Upgrade open to fix command injection vulnerabilities via unsanitized URLs and file paths on Unix, Windows, and WSL systems.

✅ 1 CVE resolved by this upgrade

This PR will resolve the following CVEs:

Issue Severity           Description
AIKIDO-2026-549490
HIGH
[open] Unsanitized URLs and file paths are passed directly to platform launchers, allowing command injection via dash-prefixed paths on Unix or PowerShell metacharacters on Windows, potentially leading to arbitrary command execution.

@cst8t
cst8t merged commit 1a64478 into v0.12.1-develop Oct 4, 2026
2 checks passed
@cst8t
cst8t deleted the fix/aikido-security-update-packages-133368473-kejp branch October 4, 2026 17:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant