Description
This affects all versions of package ps-visitor. If attacker-controlled user input is given to the kill function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.
Remediation
References
https://snyk.io/vuln/SNYK-JS-PSVISITOR-1078544
https://github.com/WisdomKwan/ps-visitor/blob/cdfc934a8e4af95aa0473f4b2a4bd091d09faf2f/index.js%23L404
Related Vulnerabilities
CVE-2020-7642 Vulnerability in maven package org.webjars.bowergithub.afarkas:lazysizes
CVE-2022-21222 Vulnerability in maven package org.webjars.npm:css-what
CVE-2023-27490 Vulnerability in npm package next-auth
CVE-2020-24750 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2023-28709 Vulnerability in maven package org.apache.tomcat:tomcat-util