Skip to content

Conversation

ohaiibuzzle
Copy link
Member

A bug was discovered that allows arbitrary command execution when running an app from PlayCover due to the code dealing with parsing entitlements did not escape the app path.

Bug was introduced in 84ce798, so it may have affected all PlayCover versions past v1.0.7

@Depal1 Depal1 merged commit fefbd1b into PlayCover:develop Dec 20, 2022
@Depal1 Depal1 mentioned this pull request Dec 20, 2022
3 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants