Description
Growl adds growl notification support to nodejs. Growl before 1.10.2 does not properly sanitize input before passing it to exec, allowing for arbitrary command execution.
Remediation
References
https://github.com/tj/node-growl/issues/60
https://github.com/tj/node-growl/pull/61
https://nodesecurity.io/advisories/146
Related Vulnerabilities
CVE-2019-10753 Vulnerability in maven package com.diffplug.gradle.spotless:spotless-eclipse-groovy
CVE-2020-14967 Vulnerability in maven package org.webjars.bowergithub.kjur:jsrsasign
CVE-2020-9484 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2022-39236 Vulnerability in npm package matrix-js-sdk
CVE-2019-9212 Vulnerability in maven package com.alipay.sofa:hessian