Description
Insufficient input validation in npm package `jison` <= 0.4.18 may lead to OS command injection attacks.
Remediation
References
https://hackerone.com/reports/690010
Related Vulnerabilities
CVE-2017-16110 Vulnerability in npm package weather.swlyons
CVE-2020-16041 Vulnerability in npm package electron
CVE-2020-7758 Vulnerability in npm package browserless-chrome
CVE-2017-16185 Vulnerability in npm package uekw1511server
CVE-2022-40152 Vulnerability in maven package com.fasterxml.woodstox:woodstox-core