Description
diskusage-ng through 0.2.4 is vulnerable to Command Injection.It allows execution of arbitrary commands via the path argument.
Remediation
References
https://github.com/iximiuz/node-diskusage-ng/blob/master/lib/posix.js#L11
https://snyk.io/vuln/SNYK-JS-DISKUSAGENG-564425
Related Vulnerabilities
CVE-2023-3691 Vulnerability in maven package org.webjars.npm:github-com-layui-layui
CVE-2021-23460 Vulnerability in npm package min-dash
CVE-2022-24814 Vulnerability in npm package directus
CVE-2022-0084 Vulnerability in maven package org.jboss.xnio:xnio-api
CVE-2020-11998 Vulnerability in maven package org.apache.activemq:activemq-broker