Description
gulp-tape through 1.0.0 allows execution of arbitrary commands. It is possible to inject arbitrary commands as part of 'gulp-tape' options.
Remediation
References
https://snyk.io/vuln/SNYK-JS-GULPTAPE-560124
Related Vulnerabilities
CVE-2023-26155 Vulnerability in npm package node-qpdf
CVE-2019-18213 Vulnerability in maven package org.lsp4xml:org.eclipse.lsp4xml.extensions.web
CVE-2023-26104 Vulnerability in npm package lite-web-server
CVE-2020-7690 Vulnerability in maven package org.webjars.npm:jspdf
CVE-2015-0250 Vulnerability in maven package org.eclipse.birt.runtime:org.apache.batik.dom