Description
umount through 1.1.6 is vulnerable to Command Injection. The argument device can be controlled by users without any sanitization.
Remediation
References
https://snyk.io/vuln/SNYK-JS-UMOUNT-564265
Related Vulnerabilities
CVE-2019-14517 Vulnerability in maven package org.webjars.bower:editor.md
CVE-2017-15695 Vulnerability in maven package org.apache.geode:geode-core
CVE-2022-39368 Vulnerability in maven package org.eclipse.californium:element-connector
CVE-2018-1000644 Vulnerability in maven package org.eclipse.rdf4j:rdf4j-rio-trix
CVE-2020-7661 Vulnerability in maven package org.webjars.npm:url-regex