Description
diskusage-ng through 0.2.4 is vulnerable to Command Injection.It allows execution of arbitrary commands via the path argument.
Remediation
References
https://github.com/iximiuz/node-diskusage-ng/blob/master/lib/posix.js#L11
https://snyk.io/vuln/SNYK-JS-DISKUSAGENG-564425
Related Vulnerabilities
CVE-2022-21676 Vulnerability in npm package engine.io
CVE-2011-4905 Vulnerability in maven package activemq:activemq-core
CVE-2022-24197 Vulnerability in maven package com.itextpdf:itext7-core
CVE-2022-45688 Vulnerability in maven package cn.hutool:hutool-json
CVE-2022-25931 Vulnerability in npm package easy-static-server