naholyr github-todos 3.1.0 is vulnerable to command injection. The range argument for the _hook subcommand is concatenated without any validation, and is directly used by the exec function.
{
"github_reviewed": true,
"github_reviewed_at": "2021-12-08T20:28:47Z",
"severity": "CRITICAL",
"nvd_published_at": "2021-12-07T00:15:00Z",
"cwe_ids": [
"CWE-78"
]
}