Description
diskusage-ng through 0.2.4 is vulnerable to Command Injection.It allows execution of arbitrary commands via the path argument.
Remediation
References
https://github.com/iximiuz/node-diskusage-ng/blob/master/lib/posix.js#L11
https://snyk.io/vuln/SNYK-JS-DISKUSAGENG-564425
Related Vulnerabilities
CVE-2021-3918 Vulnerability in npm package json-schema
CVE-2020-14966 Vulnerability in maven package org.webjars.npm:jsrsasign
CVE-2023-25576 Vulnerability in npm package @fastify/multipart
CVE-2023-26144 Vulnerability in npm package graphql
CVE-2021-22144 Vulnerability in maven package org.elasticsearch:elasticsearch