Description
enpeem through 2.2.0 allows execution of arbitrary commands. The "options.dir" argument is provided to the "exec" function without any sanitization.
Remediation
References
https://github.com/balderdashy/enpeem/blob/master/index.js#L114
https://snyk.io/vuln/SNYK-JS-ENPEEM-559007
Related Vulnerabilities
CVE-2016-7103 Vulnerability in maven package org.webjars:jquery-ui
CVE-2017-15701 Vulnerability in maven package org.apache.qpid:qpid-broker
CVE-2019-5438 Vulnerability in npm package harp
CVE-2020-26291 Vulnerability in npm package urijs
CVE-2023-40037 Vulnerability in maven package org.apache.nifi:nifi-jms-processors