Description
Concatenating unsanitized user input in the `whereis` npm module < 0.4.1 allowed an attacker to execute arbitrary commands. The `whereis` module is deprecated and it is recommended to use the `which` npm module instead.
Remediation
References
https://hackerone.com/reports/319476
Related Vulnerabilities
CVE-2018-18854 Vulnerability in maven package io.spray:spray-json_2.10
CVE-2022-21671 Vulnerability in npm package @replit/crosis
CVE-2021-23337 Vulnerability in maven package org.fujion.webjars:lodash
CVE-2022-4565 Vulnerability in maven package cn.hutool:hutool-core
CVE-2022-37767 Vulnerability in maven package io.pebbletemplates:pebble