Description
A command injection vulnerability in libnmapp package for versions <0.4.16 allows arbitrary commands to be executed via arguments to the range options.
Remediation
References
https://hackerone.com/reports/390865
Related Vulnerabilities
CVE-2020-7682 Vulnerability in npm package marked-tree
CVE-2022-21222 Vulnerability in maven package org.webjars.npm:css-what
CVE-2023-36665 Vulnerability in maven package org.webjars.npm:protobufjs
CVE-2020-28472 Vulnerability in maven package org.webjars.bower:aws-sdk
CVE-2023-33725 Vulnerability in maven package org.broadleafcommerce:broadleaf