Description
lib/cmd.js in the node-windows package before 1.0.0-beta.6 for Node.js allows command injection via the PID parameter.
Remediation
References
https://github.com/coreybutler/node-windows/compare/1.0.0-beta.5...1.0.0-beta.6
https://github.com/dwisiswant0/advisory/issues/4
https://security.netapp.com/advisory/ntap-20220107-0004/
Related Vulnerabilities
CVE-2021-25642 Vulnerability in maven package org.apache.hadoop:hadoop-yarn-server-resourcemanager
CVE-2021-39153 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2018-3757 Vulnerability in npm package pdf-image
CVE-2018-19362 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2023-40027 Vulnerability in npm package @keystone-6/core