Description
Insufficient input validation in npm package `jison` <= 0.4.18 may lead to OS command injection attacks.
Remediation
References
https://hackerone.com/reports/690010
Related Vulnerabilities
CVE-2022-22881 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-base
CVE-2021-41109 Vulnerability in npm package parse-server
CVE-2018-3735 Vulnerability in npm package bracket-template
CVE-2020-14967 Vulnerability in maven package org.webjars.bowergithub.kjur:jsrsasign
CVE-2023-26486 Vulnerability in maven package org.webjars.bowergithub.vega:vega