Description
All versions of the package vagrant.js are vulnerable to Command Injection via the boxAdd function due to improper input sanitization.
Remediation
References
https://security.snyk.io/vuln/SNYK-JS-VAGRANTJS-3175614
Related Vulnerabilities
CVE-2021-21266 Vulnerability in maven package org.openhab.addons.bundles:org.openhab.binding.ihc
CVE-2017-16150 Vulnerability in npm package wangguojing123
CVE-2023-27162 Vulnerability in maven package org.openapitools:openapi-generator-project
CVE-2020-11020 Vulnerability in npm package faye
CVE-2018-1000644 Vulnerability in maven package org.eclipse.rdf4j:rdf4j-rio-rdfxml