Description
enpeem through 2.2.0 allows execution of arbitrary commands. The "options.dir" argument is provided to the "exec" function without any sanitization.
Remediation
References
https://github.com/balderdashy/enpeem/blob/master/index.js#L114
https://snyk.io/vuln/SNYK-JS-ENPEEM-559007
Related Vulnerabilities
CVE-2017-12610 Vulnerability in maven package org.apache.kafka:kafka_2.10
CVE-2018-14730 Vulnerability in npm package browserify-hmr
CVE-2020-35209 Vulnerability in maven package io.atomix:atomix
CVE-2015-5258 Vulnerability in maven package org.springframework.social:spring-social-core
CVE-2020-13934 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core