Description
gulp-tape through 1.0.0 allows execution of arbitrary commands. It is possible to inject arbitrary commands as part of 'gulp-tape' options.
Remediation
References
https://snyk.io/vuln/SNYK-JS-GULPTAPE-560124
Related Vulnerabilities
CVE-2023-46496 Vulnerability in npm package @evershop/evershop
CVE-2020-7715 Vulnerability in npm package deep-get-set
CVE-2016-10707 Vulnerability in maven package org.webjars:jquery
CVE-2022-25883 Vulnerability in maven package org.webjars.npm:semver
CVE-2022-1291 Vulnerability in maven package org.webjars.bower:tableexport.jquery.plugin