Description
Growl adds growl notification support to nodejs. Growl before 1.10.2 does not properly sanitize input before passing it to exec, allowing for arbitrary command execution.
Remediation
References
https://github.com/tj/node-growl/issues/60
https://github.com/tj/node-growl/pull/61
https://nodesecurity.io/advisories/146
Related Vulnerabilities
CVE-2019-19771 Vulnerability in npm package bs58chekc
CVE-2021-39135 Vulnerability in npm package @npmcli/arborist
CVE-2010-2076 Vulnerability in maven package org.apache.cxf:cxf-bundle-minimal
CVE-2020-1948 Vulnerability in maven package org.apache.dubbo:dubbo-rpc
CVE-2023-40787 Vulnerability in maven package org.springblade:blade-core-tool