Description
Growl adds growl notification support to nodejs. Growl before 1.10.2 does not properly sanitize input before passing it to exec, allowing for arbitrary command execution.
Remediation
References
https://nodesecurity.io/advisories/146
https://github.com/tj/node-growl/pull/61
https://github.com/tj/node-growl/issues/60
Related Vulnerabilities
CVE-2023-40338 Vulnerability in maven package org.jenkins-ci.plugins:cloudbees-folder
CVE-2021-21293 Vulnerability in maven package org.http4s:blaze-core_2.12
CVE-2017-0783 Vulnerability in maven package org.apache.openmeetings:openmeetings-web
CVE-2022-23647 Vulnerability in npm package prismjs
CVE-2020-7760 Vulnerability in maven package org.webjars.bowergithub.codemirror:codemirror