Description
Haraka version 2.8.8 and earlier comes with a plugin for processing attachments for zip files. Versions 2.8.8 and earlier can be vulnerable to command injection.
Remediation
References
https://github.com/outflanknl/Exploits/blob/master/harakiri-CVE-2016-1000282.py
Related Vulnerabilities
CVE-2017-16091 Vulnerability in npm package xtalk
CVE-2021-23376 Vulnerability in npm package ffmpegdotjs
CVE-2023-49276 Vulnerability in npm package uptime-kuma
CVE-2021-21353 Vulnerability in npm package pug
CVE-2022-22880 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-base-core