Description
umount through 1.1.6 is vulnerable to Command Injection. The argument device can be controlled by users without any sanitization.
Remediation
References
https://snyk.io/vuln/SNYK-JS-UMOUNT-564265
Related Vulnerabilities
CVE-2021-4307 Vulnerability in maven package org.webjars.npm:baobab
CVE-2020-26282 Vulnerability in maven package com.browserup:browserup-proxy-rest
CVE-2019-9153 Vulnerability in npm package openpgp
CVE-2018-1000531 Vulnerability in maven package com.inversoft:prime-jwt
CVE-2019-10768 Vulnerability in maven package org.webjars.bower:angular