Description
A command injection vulnerability in libnmapp package for versions <0.4.16 allows arbitrary commands to be executed via arguments to the range options.
Remediation
References
https://hackerone.com/reports/390865
Related Vulnerabilities
CVE-2021-37306 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-base
CVE-2018-3737 Vulnerability in maven package org.webjars.npm:sshpk
CVE-2023-26144 Vulnerability in npm package graphql
CVE-2023-7078 Vulnerability in npm package miniflare
CVE-2021-34435 Vulnerability in npm package @theia/mini-browser