Description
All versions of package launchpad are vulnerable to Command Injection via stop.
Remediation
References
https://github.com/bitovi/launchpad/issues/123%23issuecomment-732188118
https://github.com/bitovi/launchpad/pull/124
https://snyk.io/vuln/SNYK-JS-LAUNCHPAD-1044065
Related Vulnerabilities
CVE-2019-18797 Vulnerability in maven package org.webjars.npm:node-sass
CVE-2021-37695 Vulnerability in npm package ckeditor4
CVE-2023-40349 Vulnerability in maven package org.jenkins-ci.plugins:gogs-webhook
CVE-2016-8745 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2021-23397 Vulnerability in npm package @ianwalter/merge