Description
promise-probe before 0.10.0 allows remote attackers to perform a command injection attack. The file, outputFile and options functions can be controlled by users without any sanitization.
Remediation
References
https://github.com/dottgonzo/node-promise-probe/commit/0d9affb67fc1ad985903536d35372cf55efe5a45%2C
https://snyk.io/vuln/SNYK-JS-PROMISEPROBE-546816
Related Vulnerabilities
CVE-2020-15130 Vulnerability in npm package slpjs
CVE-2023-22467 Vulnerability in maven package org.webjars.bowergithub.moment:luxon
CVE-2023-49276 Vulnerability in npm package uptime-kuma
CVE-2023-40815 Vulnerability in maven package org.opencrx:opencrx-core-models
CVE-2022-38751 Vulnerability in maven package org.yaml:snakeyaml