Description
umount through 1.1.6 is vulnerable to Command Injection. The argument device can be controlled by users without any sanitization.
Remediation
References
https://snyk.io/vuln/SNYK-JS-UMOUNT-564265
Related Vulnerabilities
CVE-2016-3506 Vulnerability in maven package com.oracle:ojdbc7
CVE-2023-49486 Vulnerability in maven package com.jfinal:jfinal
CVE-2017-16102 Vulnerability in npm package serverhuwenhui
CVE-2018-16487 Vulnerability in maven package org.webjars.npm:lodash.merge
CVE-2019-10314 Vulnerability in maven package org.jenkins-ci.plugins:koji