Description
lib/cmd.js in the node-windows package before 1.0.0-beta.6 for Node.js allows command injection via the PID parameter.
Remediation
References
https://github.com/coreybutler/node-windows/compare/1.0.0-beta.5...1.0.0-beta.6
https://github.com/dwisiswant0/advisory/issues/4
https://security.netapp.com/advisory/ntap-20220107-0004/
Related Vulnerabilities
CVE-2019-13506 Vulnerability in npm package @nuxtjs/devalue
CVE-2021-33605 Vulnerability in maven package com.vaadin:vaadin-checkbox-flow
CVE-2022-2064 Vulnerability in npm package nocodb
CVE-2023-45648 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2022-28158 Vulnerability in maven package com.surenpi.jenkins:phoenix-autotest