Install Package Project maintains a narrowly focused software packaging and installation utility, reflecting a specialized role within the broader software distribution ecosystem. Current exposure counts, severity distribution, and any confirmed exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Install Package Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-7629CRITICAL install-package through 0.4.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the options argument. | Apr 2, 2020 | 9.8 | 32 | NO | NO |
CVE-2020-7628CRITICAL umount through 1.1.6 is vulnerable to Command Injection. The argument device can be controlled by users without any sanitization. | Apr 2, 2020 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Install Package Project.
Media articles that mention a CVE ID that affects a product developed by Install Package Project — matched by CVE ID, not by vendor name.