Description
effect through 1.0.4 is vulnerable to Command Injection. It allows execution of arbitrary command via the options argument.
Remediation
References
https://github.com/Javascipt/effect/blob/master/helper.js#L24%2C
https://snyk.io/vuln/SNYK-JS-EFFECT-564256
Related Vulnerabilities
CVE-2023-24057 Vulnerability in maven package ca.uhn.hapi.fhir:org.hl7.fhir.r5
CVE-2020-28052 Vulnerability in maven package bouncycastle:bcprov-jdk14
CVE-2022-31129 Vulnerability in npm package moment
CVE-2021-25912 Vulnerability in npm package dotty
CVE-2023-47320 Vulnerability in maven package org.silverpeas.core:silverpeas-core-war