Description
umount through 1.1.6 is vulnerable to Command Injection. The argument device can be controlled by users without any sanitization.
Remediation
References
https://snyk.io/vuln/SNYK-JS-UMOUNT-564265
Related Vulnerabilities
CVE-2022-21186 Vulnerability in npm package @acrontum/filesystem-template
CVE-2019-14900 Vulnerability in maven package org.hibernate:hibernate-core
CVE-2017-8028 Vulnerability in maven package org.springframework.ldap:spring-ldap-core
CVE-2022-23496 Vulnerability in maven package nl.basjes.parse.useragent:yauaa-snowflake