Description
gulp-tape through 1.0.0 allows execution of arbitrary commands. It is possible to inject arbitrary commands as part of 'gulp-tape' options.
Remediation
References
https://snyk.io/vuln/SNYK-JS-GULPTAPE-560124
Related Vulnerabilities
CVE-2022-31175 Vulnerability in npm package @ckeditor/ckeditor5-html-support
CVE-2022-4725 Vulnerability in maven package com.amazonaws:aws-android-sdk-core
CVE-2022-23945 Vulnerability in maven package org.apache.shenyu:shenyu-common
CVE-2021-32850 Vulnerability in npm package @claviska/jquery-minicolors
CVE-2023-36479 Vulnerability in maven package org.eclipse.jetty.ee9:jetty-ee9-servlets