Description
effect through 1.0.4 is vulnerable to Command Injection. It allows execution of arbitrary command via the options argument.
Remediation
References
https://snyk.io/vuln/SNYK-JS-EFFECT-564256
https://github.com/Javascipt/effect/blob/master/helper.js#L24%2C
Related Vulnerabilities
CVE-2023-49448 Vulnerability in maven package com.jfinal:jfinal
CVE-2022-43433 Vulnerability in maven package io.jenkins.plugins:screenrecorder
CVE-2023-44487 Vulnerability in maven package io.helidon.http:helidon-http-http2
CVE-2023-3691 Vulnerability in maven package org.webjars.bowergithub.layui:layui