Description
closure-compiler-stream through 0.1.15 allows execution of arbitrary commands. The argument "options" of the exports function in "index.js" can be controlled by users without any sanitization.
Remediation
References
https://snyk.io/vuln/SNYK-JS-CLOSURECOMPILERSTREAM-560123
Related Vulnerabilities
CVE-2020-7646 Vulnerability in npm package curlrequest
CVE-2020-11059 Vulnerability in npm package aegir
CVE-2023-3696 Vulnerability in maven package org.webjars.npm:mongoose
CVE-2009-3579 Vulnerability in maven package org.mortbay.jetty:jetty
CVE-2023-24621 Vulnerability in maven package com.esotericsoftware.yamlbeans:yamlbeans