Code injection in stanford-parser
        
  Critical severity
        
          GitHub Reviewed
      
        Published
          Jul 28, 2023 
          to the GitHub Advisory Database
          •
          Updated Sep 5, 2024 
      
  
Description
        Published by the National Vulnerability Database
      Jul 28, 2023 
    
  
        Published to the GitHub Advisory Database
      Jul 28, 2023 
    
  
        Reviewed
      Jul 28, 2023 
    
  
        Last updated
      Sep 5, 2024 
    
  
stanford-parser v3.9.2 and below was discovered to contain a code injection vulnerability in the component edu.stanford.nlp.io.getBZip2PipedInputStream. This vulnerability is exploited via passing an unchecked argument.
References