Description
umount through 1.1.6 is vulnerable to Command Injection. The argument device can be controlled by users without any sanitization.
Remediation
References
https://snyk.io/vuln/SNYK-JS-UMOUNT-564265
Related Vulnerabilities
CVE-2016-10542 Vulnerability in maven package org.webjars.npm:ws
CVE-2020-7704 Vulnerability in npm package linux-cmdline
CVE-2019-10377 Vulnerability in maven package net.hurstfrost.jenkins:avatar
CVE-2018-8010 Vulnerability in maven package org.apache.solr:solr-core
CVE-2021-23337 Vulnerability in maven package org.webjars.bowergithub.lodash:lodash