Description
umount through 1.1.6 is vulnerable to Command Injection. The argument device can be controlled by users without any sanitization.
Remediation
References
https://snyk.io/vuln/SNYK-JS-UMOUNT-564265
Related Vulnerabilities
CVE-2019-3773 Vulnerability in maven package org.springframework.ws:spring-xml
CVE-2016-10735 Vulnerability in maven package org.jszip.redist:bootstrap
CVE-2017-18197 Vulnerability in maven package org.webjars.bower:mxgraph
CVE-2012-2098 Vulnerability in maven package org.apache.commons:commons-compress