Description
The pdfinfojs NPM module versions <= 0.3.6 has a command injection vulnerability that allows an attacker to execute arbitrary commands on the victim's machine.
Remediation
References
https://hackerone.com/reports/330957
Related Vulnerabilities
CVE-2019-15532 Vulnerability in npm package cyberchef
CVE-2018-3766 Vulnerability in npm package buttle
CVE-2022-23619 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web
CVE-2020-7649 Vulnerability in npm package snyk-broker
CVE-2019-5448 Vulnerability in maven package org.webjars.npm:yarn