Description
The pdfinfojs NPM module versions <= 0.3.6 has a command injection vulnerability that allows an attacker to execute arbitrary commands on the victim's machine.
Remediation
References
https://hackerone.com/reports/330957
Related Vulnerabilities
CVE-2022-36091 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web-templates
CVE-2020-15131 Vulnerability in npm package slp-validate
CVE-2020-28282 Vulnerability in maven package org.webjars.npm:getobject
CVE-2021-41189 Vulnerability in maven package org.dspace:dspace-api
CVE-2019-10744 Vulnerability in maven package org.fujion.webjars:lodash