Blamer Project maintains a narrowly scoped command-line utility product focused on version-control blame tracking and source-code annotation, where the durable signal centers on injection-class vulnerabilities spanning code injection, argument injection, and OS command injection. These weakness classes reflect the product's role in parsing and executing external commands and processing user-supplied input at the system boundary. Current exploitation activity, severity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Blamer Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-10807CRITICAL Blamer versions prior to 1.0.1 allows execution of arbitrary commands. It is possible to inject arbitrary commands as part of the arguments provided to blamer. | Mar 11, 2020 | 9.8 | 31 | NO | NO |
CVE-2023-26143CRITICAL Versions of the package blamer before 1.0.4 are vulnerable to Arbitrary Argument Injection via the blameByFile() API. The library does not sanitize for user input or validate the g | Sep 19, 2023 | 9.1 | 29 | NO | NO |
CVE-2020-8137CRITICAL Code injection vulnerability in blamer 1.0.0 and earlier may result in remote code execution when the input can be controlled by an attacker. | Mar 20, 2020 | 9.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Blamer Project.
Media articles that mention a CVE ID that affects a product developed by Blamer Project — matched by CVE ID, not by vendor name.