Elvish vulnerable to remote code execution via the web UI backend in github.com/elves/elvish
{ "review_status": "UNREVIEWED", "url": "https://pkg.go.dev/vuln/GO-2022-0937" }
"https://vuln.go.dev/ID/GO-2022-0937.json"