Description
closure-compiler-stream through 0.1.15 allows execution of arbitrary commands. The argument "options" of the exports function in "index.js" can be controlled by users without any sanitization.
Remediation
References
https://snyk.io/vuln/SNYK-JS-CLOSURECOMPILERSTREAM-560123
Related Vulnerabilities
CVE-2018-3723 Vulnerability in npm package defaults-deep
CVE-2022-23496 Vulnerability in maven package nl.basjes.parse.useragent:yauaa
CVE-2021-23397 Vulnerability in npm package @ianwalter/merge
CVE-2022-34113 Vulnerability in maven package io.dataease:dataease-plugin-common
CVE-2019-10759 Vulnerability in maven package org.webjars.npm:safer-eval