Description
This affects all versions of package calipso. It is possible for a malicious module to overwrite files on an arbitrary file system through the module install functionality.
Remediation
References
https://github.com/cliftonc/calipso
https://snyk.io/vuln/SNYK-JS-CALIPSO-1300555
Related Vulnerabilities
CVE-2016-1000338 Vulnerability in maven package org.bouncycastle:bcprov-jdk15on
CVE-2022-31159 Vulnerability in maven package com.amazonaws:aws-java-sdk-s3
CVE-2017-16137 Vulnerability in npm package debug
CVE-2022-1330 Vulnerability in maven package org.webjars.bowergithub.alvarotrigo:fullpage.js
CVE-2020-6836 Vulnerability in maven package org.webjars.npm:hot-formula-parser