Description
closure-compiler-stream through 0.1.15 allows execution of arbitrary commands. The argument "options" of the exports function in "index.js" can be controlled by users without any sanitization.
Remediation
References
https://snyk.io/vuln/SNYK-JS-CLOSURECOMPILERSTREAM-560123
Related Vulnerabilities
CVE-2018-9207 Vulnerability in maven package org.webjars:jquery-file-upload
CVE-2021-26117 Vulnerability in maven package org.apache.activemq:artemis-server
CVE-2020-15174 Vulnerability in maven package org.webjars.npm:electron
CVE-2018-20595 Vulnerability in maven package org.hswebframework.web:hsweb-system-oauth2-client-web
CVE-2022-26336 Vulnerability in maven package org.apache.poi:poi-scratchpad