Description
All versions of the package vagrant.js are vulnerable to Command Injection via the boxAdd function due to improper input sanitization.
Remediation
References
https://security.snyk.io/vuln/SNYK-JS-VAGRANTJS-3175614
Related Vulnerabilities
CVE-2020-36378 Vulnerability in npm package aaptjs
CVE-2020-8125 Vulnerability in maven package org.webjars.npm:klona
CVE-2020-15250 Vulnerability in maven package junit:junit
CVE-2017-4952 Vulnerability in maven package com.vmware.xenon:xenon-common
CVE-2019-0195 Vulnerability in maven package org.apache.tapestry:tapestry-core