Description
The package p4 before 0.0.7 are vulnerable to Command Injection via the run() function due to improper input sanitization
Remediation
References
https://github.com/natelong/p4/blob/master/p4.js%23L12
https://github.com/natelong/p4/commit/ae42e251beabf67c00539ec0e1d7aa149ca445fb
https://security.snyk.io/vuln/SNYK-JS-P4-3167330
Related Vulnerabilities
CVE-2021-23507 Vulnerability in npm package object-path-set
CVE-2019-17579 Vulnerability in maven package org.sonarsource.sonarqube:sonar-web
CVE-2017-1000498 Vulnerability in maven package com.caverock:androidsvg
CVE-2020-13956 Vulnerability in maven package org.apache.httpcomponents:httpclient
CVE-2022-3509 Vulnerability in maven package com.google.protobuf:protobuf-java