Description
All versions of package launchpad are vulnerable to Command Injection via stop.
Remediation
References
https://github.com/bitovi/launchpad/issues/123%23issuecomment-732188118
https://github.com/bitovi/launchpad/pull/124
https://snyk.io/vuln/SNYK-JS-LAUNCHPAD-1044065
Related Vulnerabilities
CVE-2020-7683 Vulnerability in npm package rollup-plugin-server
CVE-2022-31089 Vulnerability in npm package parse-server
CVE-2021-38384 Vulnerability in npm package serverless-offline
CVE-2022-35961 Vulnerability in maven package org.webjars.npm:openzeppelin__contracts
CVE-2019-10330 Vulnerability in maven package org.jenkins-ci.plugins:gitea