Description
Growl adds growl notification support to nodejs. Growl before 1.10.2 does not properly sanitize input before passing it to exec, allowing for arbitrary command execution.
Remediation
References
https://github.com/tj/node-growl/issues/60
https://github.com/tj/node-growl/pull/61
https://nodesecurity.io/advisories/146
Related Vulnerabilities
CVE-2021-31412 Vulnerability in maven package com.vaadin:flow-server
CVE-2021-32809 Vulnerability in maven package org.webjars.bowergithub.ckeditor:ckeditor4
CVE-2017-16132 Vulnerability in npm package simple-npm-registry
CVE-2018-14719 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2022-37767 Vulnerability in maven package io.pebbletemplates:pebble