Description
enpeem through 2.2.0 allows execution of arbitrary commands. The "options.dir" argument is provided to the "exec" function without any sanitization.
Remediation
References
https://github.com/balderdashy/enpeem/blob/master/index.js#L114
https://snyk.io/vuln/SNYK-JS-ENPEEM-559007
Related Vulnerabilities
CVE-2021-23364 Vulnerability in npm package browserslist
CVE-2019-13343 Vulnerability in maven package com.butor:portal
CVE-2020-14061 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2017-16088 Vulnerability in npm package safe-eval
CVE-2018-9206 Vulnerability in maven package org.webjars.bower:blueimp-file-upload