Description
enpeem through 2.2.0 allows execution of arbitrary commands. The "options.dir" argument is provided to the "exec" function without any sanitization.
Remediation
References
https://github.com/balderdashy/enpeem/blob/master/index.js#L114
https://snyk.io/vuln/SNYK-JS-ENPEEM-559007
Related Vulnerabilities
CVE-2016-10625 Vulnerability in npm package headless-browser-lite
CVE-2021-28168 Vulnerability in maven package org.glassfish.jersey.core:jersey-common
CVE-2021-46708 Vulnerability in maven package org.webjars.npm:swagger-ui
CVE-2020-16024 Vulnerability in maven package org.webjars.npm:electron
CVE-2022-43670 Vulnerability in maven package org.apache.sling:org.apache.sling.cms