Description
Growl adds growl notification support to nodejs. Growl before 1.10.2 does not properly sanitize input before passing it to exec, allowing for arbitrary command execution.
Remediation
References
https://github.com/tj/node-growl/issues/60
https://github.com/tj/node-growl/pull/61
https://nodesecurity.io/advisories/146
Related Vulnerabilities
CVE-2018-3745 Vulnerability in maven package org.webjars.npm:atob
CVE-2019-17359 Vulnerability in maven package org.bouncycastle:bcprov-jdk15on
CVE-2020-23622 Vulnerability in maven package org.fourthline.cling:cling-core
CVE-2016-4464 Vulnerability in maven package org.apache.cxf.fediz:fediz-core
CVE-2023-26487 Vulnerability in maven package org.webjars.bowergithub.vega:vega