Description
All versions of the package create-choo-app3 are vulnerable to Command Injection via the devInstall function due to improper user-input sanitization.
Remediation
References
https://security.snyk.io/vuln/SNYK-JS-CREATECHOOAPP3-3157951
Related Vulnerabilities
CVE-2023-37913 Vulnerability in maven package org.xwiki.platform:xwiki-platform-office-importer
CVE-2022-31053 Vulnerability in maven package com.clever-cloud:biscuit-java
CVE-2021-23445 Vulnerability in npm package datatables.net
CVE-2017-11554 Vulnerability in npm package node-sass
CVE-2022-25940 Vulnerability in maven package org.webjars.npm:lite-server