Description
A code injection exists in node-df v0.1.4 that can allow an attacker to remote code execution by unsanitized input.
Remediation
References
https://hackerone.com/reports/703412
Related Vulnerabilities
CVE-2021-21349 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2021-21172 Vulnerability in maven package org.webjars.npm:electron
CVE-2022-23496 Vulnerability in maven package nl.basjes.parse.useragent:yauaa-beam-sql
CVE-2023-26122 Vulnerability in npm package safe-eval
CVE-2017-16083 Vulnerability in npm package node-simple-router