Description
The pdfinfojs NPM module versions <= 0.3.6 has a command injection vulnerability that allows an attacker to execute arbitrary commands on the victim's machine.
Remediation
References
https://hackerone.com/reports/330957
Related Vulnerabilities
CVE-2022-0144 Vulnerability in npm package shelljs
CVE-2020-2229 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2021-43788 Vulnerability in npm package nodebb
CVE-2022-35143 Vulnerability in npm package raneto
CVE-2020-24855 Vulnerability in npm package @easy-team/easywebpack-cli