Description
diskusage-ng through 0.2.4 is vulnerable to Command Injection.It allows execution of arbitrary commands via the path argument.
Remediation
References
https://github.com/iximiuz/node-diskusage-ng/blob/master/lib/posix.js#L11
https://snyk.io/vuln/SNYK-JS-DISKUSAGENG-564425
Related Vulnerabilities
CVE-2020-7760 Vulnerability in maven package org.webjars:codemirror
CVE-2022-47551 Vulnerability in maven package io.apiman:apiman-common-config
CVE-2023-50102 Vulnerability in maven package com.jfinal:jfinal
CVE-2022-1291 Vulnerability in maven package org.webjars.npm:tableexport.jquery.plugin
CVE-2023-51075 Vulnerability in maven package cn.hutool:hutool-core