Description
The gnuplot package prior to version 0.1.0 for Node.js allows code execution via shell metacharacters in Gnuplot commands.
Remediation
References
https://github.com/rkesters/gnuplot/commit/23671d4d3d28570fb19a936a6328bfac742410de
https://www.npmjs.com/package/%40rkesters/gnuplot
Related Vulnerabilities
CVE-2020-15270 Vulnerability in npm package parse-server
CVE-2021-42340 Vulnerability in maven package org.apache.tomcat:tomcat-websocket
CVE-2021-23353 Vulnerability in maven package org.webjars:jspdf
CVE-2022-39322 Vulnerability in npm package @keystone-6/core
CVE-2014-7810 Vulnerability in maven package org.mortbay.jasper:apache-jsp