Description
The package p4 before 0.0.7 are vulnerable to Command Injection via the run() function due to improper input sanitization
Remediation
References
https://security.snyk.io/vuln/SNYK-JS-P4-3167330
https://github.com/natelong/p4/blob/master/p4.js%23L12
https://github.com/natelong/p4/commit/ae42e251beabf67c00539ec0e1d7aa149ca445fb
Related Vulnerabilities
CVE-2022-29078 Vulnerability in npm package ejs
CVE-2022-24819 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web-templates
CVE-2022-24847 Vulnerability in maven package org.geoserver:gs-main
CVE-2022-0401 Vulnerability in npm package w-zip
CVE-2018-20677 Vulnerability in maven package org.webjars:bootstrap-sass