Description
Lack of output sanitization allowed an attack to execute arbitrary shell commands via the logkitty npm package before version 0.7.1.
Remediation
References
https://hackerone.com/reports/825729
Related Vulnerabilities
CVE-2020-15232 Vulnerability in maven package org.mapfish.print:print-standalone
CVE-2020-7755 Vulnerability in npm package dat.gui
CVE-2023-26120 Vulnerability in maven package com.xuxueli:xxl-job
CVE-2021-26073 Vulnerability in npm package atlassian-connect-express
CVE-2020-28168 Vulnerability in maven package org.webjars.bowergithub.axios:axios