Description
enpeem through 2.2.0 allows execution of arbitrary commands. The "options.dir" argument is provided to the "exec" function without any sanitization.
Remediation
References
https://github.com/balderdashy/enpeem/blob/master/index.js#L114
https://snyk.io/vuln/SNYK-JS-ENPEEM-559007
Related Vulnerabilities
CVE-2022-1233 Vulnerability in maven package org.webjars.bower:urijs
CVE-2017-5617 Vulnerability in maven package org.openstreetmap.josm:josm
CVE-2022-22965 Vulnerability in maven package org.springframework:spring-webflux
CVE-2020-6428 Vulnerability in npm package electron
CVE-2020-35217 Vulnerability in maven package io.vertx:vertx-web