Description
Insufficient input validation in npm package `jison` <= 0.4.18 may lead to OS command injection attacks.
Remediation
References
https://hackerone.com/reports/690010
Related Vulnerabilities
CVE-2021-27515 Vulnerability in npm package url-parse
CVE-2020-6449 Vulnerability in maven package org.webjars.npm:electron
CVE-2020-26870 Vulnerability in npm package dompurify
CVE-2020-7627 Vulnerability in npm package node-key-sender
CVE-2022-36886 Vulnerability in maven package org.jenkins-ci.plugins:external-monitor-job