Description
Command injection exists in pdf-image v2.0.0 due to an unescaped string parameter.
Remediation
References
https://github.com/roest01/node-pdf-image/commit/54679496a89738443917608c2bbe2f6e5dd20e83
https://hackerone.com/reports/340208
Related Vulnerabilities
CVE-2020-28272 Vulnerability in npm package keyget
CVE-2020-6506 Vulnerability in npm package react-native-webview
CVE-2020-28502 Vulnerability in maven package org.webjars.npm:xmlhttprequest-ssl
CVE-2020-14968 Vulnerability in maven package org.webjars.bower:jsrsasign
CVE-2020-28168 Vulnerability in maven package org.webjars.bowergithub.axios:axios