Description
Growl adds growl notification support to nodejs. Growl before 1.10.2 does not properly sanitize input before passing it to exec, allowing for arbitrary command execution.
Remediation
References
https://github.com/tj/node-growl/issues/60
https://github.com/tj/node-growl/pull/61
https://nodesecurity.io/advisories/146
Related Vulnerabilities
CVE-2021-46366 Vulnerability in maven package info.magnolia:magnolia-core
CVE-2017-16030 Vulnerability in npm package useragent
CVE-2018-1000820 Vulnerability in maven package org.neo4j.procedure:apoc
CVE-2022-35954 Vulnerability in npm package @actions/core
CVE-2020-15366 Vulnerability in maven package org.webjars.npm:ajv