Description
All versions of the package create-choo-app3 are vulnerable to Command Injection via the devInstall function due to improper user-input sanitization.
Remediation
References
https://security.snyk.io/vuln/SNYK-JS-CREATECHOOAPP3-3157951
Related Vulnerabilities
CVE-2019-12043 Vulnerability in maven package org.webjars.bowergithub.jonschlinkert:remarkable
CVE-2022-26112 Vulnerability in maven package org.apache.pinot:pinot-broker
CVE-2021-3795 Vulnerability in npm package semver-regex
CVE-2022-1274 Vulnerability in maven package org.keycloak:keycloak-services
CVE-2021-36372 Vulnerability in maven package org.apache.ozone:ozone-common