Description
Growl adds growl notification support to nodejs. Growl before 1.10.2 does not properly sanitize input before passing it to exec, allowing for arbitrary command execution.
Remediation
References
https://nodesecurity.io/advisories/146
https://github.com/tj/node-growl/pull/61
https://github.com/tj/node-growl/issues/60
Related Vulnerabilities
CVE-2019-1003086 Vulnerability in maven package org.jenkins-ci.plugins:sinatra-chef-builder
CVE-2017-16170 Vulnerability in npm package liuyaserver
CVE-2020-7631 Vulnerability in npm package diskusage-ng
CVE-2016-4055 Vulnerability in npm package moment
CVE-2019-13000 Vulnerability in maven package fr.acinq.eclair:eclair-core_2.11