Description
An unintended require vulnerability in script-manager npm package version 0.8.6 and earlier may allow attackers to execute arbitrary code.
Remediation
References
https://hackerone.com/reports/660563
Related Vulnerabilities
CVE-2021-46708 Vulnerability in maven package org.webjars.npm:swagger-ui-dist
CVE-2023-45135 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web-war
CVE-2022-31129 Vulnerability in maven package org.webjars.bower:momentjs
CVE-2020-17519 Vulnerability in maven package org.apache.flink:flink-runtime_2.11
CVE-2018-17960 Vulnerability in maven package org.webjars.npm:ckeditor