Description
gulp-tape through 1.0.0 allows execution of arbitrary commands. It is possible to inject arbitrary commands as part of 'gulp-tape' options.
Remediation
References
https://snyk.io/vuln/SNYK-JS-GULPTAPE-560124
Related Vulnerabilities
CVE-2022-25758 Vulnerability in npm package scss-tokenizer
CVE-2021-23391 Vulnerability in npm package calipso
CVE-2020-8132 Vulnerability in npm package pdf-image
CVE-2023-40815 Vulnerability in maven package org.opencrx:opencrx-core-models
CVE-2020-1956 Vulnerability in maven package org.apache.kylin:kylin-core-common