Description
effect through 1.0.4 is vulnerable to Command Injection. It allows execution of arbitrary command via the options argument.
Remediation
References
https://github.com/Javascipt/effect/blob/master/helper.js#L24%2C
https://snyk.io/vuln/SNYK-JS-EFFECT-564256
Related Vulnerabilities
CVE-2021-23376 Vulnerability in npm package ffmpegdotjs
CVE-2022-43427 Vulnerability in maven package com.compuware.jenkins:compuware-topaz-for-total-test
CVE-2020-8237 Vulnerability in maven package org.webjars.bower:json-bigint
CVE-2014-0002 Vulnerability in maven package org.apache.camel:camel-core
CVE-2020-7746 Vulnerability in maven package org.webjars.npm:chart.js