Description
effect through 1.0.4 is vulnerable to Command Injection. It allows execution of arbitrary command via the options argument.
Remediation
References
https://github.com/Javascipt/effect/blob/master/helper.js#L24%2C
https://snyk.io/vuln/SNYK-JS-EFFECT-564256
Related Vulnerabilities
CVE-2020-8176 Vulnerability in npm package koa-shopify-auth
CVE-2017-16158 Vulnerability in npm package dcserver
CVE-2023-28155 Vulnerability in npm package request
CVE-2016-10703 Vulnerability in maven package org.webjars.npm:ecstatic
CVE-2023-34840 Vulnerability in npm package angular-ui-notification