Related Vulnerabilities: CVE-2021-21372  

In Nimble before version 0.13.0, doCmd can be leveraged to execute arbitrary commands. An attacker can craft a malicious entry in the packages.json package list to trigger code execution.

Severity High

Remote Yes

Type Arbitrary command execution

Description

In Nimble before version 0.13.0, doCmd can be leveraged to execute arbitrary commands. An attacker can craft a malicious entry in the packages.json package list to trigger code execution.

AVG-1842 nimble 1:0.12.0-1 High Vulnerable

https://github.com/nim-lang/security/security/advisories/GHSA-rg9f-w24h-962p
https://consensys.net/diligence/vulnerabilities/nim-insecure-ssl-tls-defaults-remote-code-execution/
https://github.com/nim-lang/nimble/commit/7bd63d504a4157b8ed61a51af47fb086ee818c37