Description
Growl adds growl notification support to nodejs. Growl before 1.10.2 does not properly sanitize input before passing it to exec, allowing for arbitrary command execution.
Remediation
References
https://github.com/tj/node-growl/issues/60
https://github.com/tj/node-growl/pull/61
https://nodesecurity.io/advisories/146
Related Vulnerabilities
CVE-2021-43795 Vulnerability in maven package com.linecorp.armeria:armeria
CVE-2023-30521 Vulnerability in maven package org.jenkins-ci.plugins:assembla-merge-request-builder
CVE-2018-11093 Vulnerability in npm package @ckeditor/ckeditor5-link
CVE-2018-11798 Vulnerability in maven package org.apache.thrift:libthrift