Description
diskusage-ng through 0.2.4 is vulnerable to Command Injection.It allows execution of arbitrary commands via the path argument.
Remediation
References
https://github.com/iximiuz/node-diskusage-ng/blob/master/lib/posix.js#L11
https://snyk.io/vuln/SNYK-JS-DISKUSAGENG-564425
Related Vulnerabilities
CVE-2020-10544 Vulnerability in maven package org.primefaces:primefaces
CVE-2020-28052 Vulnerability in maven package bouncycastle:bcprov-jdk14
CVE-2018-16491 Vulnerability in npm package node.extend
CVE-2020-7687 Vulnerability in npm package fast-http
CVE-2022-31129 Vulnerability in maven package org.webjars.npm:moment