Description
A command injection vulnerability in the `devcert` module may lead to remote code execution when users of the module pass untrusted input to the `certificateFor` function.
Remediation
References
https://hackerone.com/reports/863544
Related Vulnerabilities
CVE-2020-24164 Vulnerability in maven package com.taoensso:nippy
CVE-2020-7643 Vulnerability in npm package paypal-adaptive
CVE-2020-28249 Vulnerability in npm package joplin
CVE-2018-3713 Vulnerability in npm package angular-http-server
CVE-2020-7733 Vulnerability in maven package org.webjars.npm:ua-parser-js