Description
All versions of package launchpad are vulnerable to Command Injection via stop.
Remediation
References
https://github.com/bitovi/launchpad/issues/123%23issuecomment-732188118
https://github.com/bitovi/launchpad/pull/124
https://snyk.io/vuln/SNYK-JS-LAUNCHPAD-1044065
Related Vulnerabilities
CVE-2018-20822 Vulnerability in maven package org.webjars.npm:node-sass
CVE-2022-37264 Vulnerability in npm package steal
CVE-2016-10645 Vulnerability in npm package grunt-images
CVE-2016-9177 Vulnerability in maven package com.sparkjava:spark-core
CVE-2021-41182 Vulnerability in maven package org.webjars.npm:jquery-ui