The file preview functionality in Sketch 0.6.12 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the filename of an encapsulated Postscript (EPS) file.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Sketch | Sketch | 0.6.12 (including) | 0.6.12 (including) |