Description
Growl adds growl notification support to nodejs. Growl before 1.10.2 does not properly sanitize input before passing it to exec, allowing for arbitrary command execution.
Remediation
References
https://github.com/tj/node-growl/issues/60
https://github.com/tj/node-growl/pull/61
https://nodesecurity.io/advisories/146
Related Vulnerabilities
CVE-2020-28500 Vulnerability in npm package lodash
CVE-2023-45282 Vulnerability in npm package openmct
CVE-2020-24025 Vulnerability in maven package org.webjars.npm:node-sass
CVE-2011-4343 Vulnerability in maven package org.apache.myfaces.core:myfaces-api
CVE-2022-28156 Vulnerability in maven package com.surenpi.jenkins:phoenix-autotest