Description
gulp-tape through 1.0.0 allows execution of arbitrary commands. It is possible to inject arbitrary commands as part of 'gulp-tape' options.
Remediation
References
https://snyk.io/vuln/SNYK-JS-GULPTAPE-560124
Related Vulnerabilities
CVE-2020-7691 Vulnerability in npm package jspdf
CVE-2016-10707 Vulnerability in maven package org.webjars.bower:jquery
CVE-2023-49375 Vulnerability in maven package com.jfinal:jfinal
CVE-2022-48285 Vulnerability in npm package jszip
CVE-2022-2596 Vulnerability in maven package org.webjars.npm:node-fetch