Description
Versions of the package window-control before 1.4.5 are vulnerable to Command Injection via the sendKeys function, due to improper input sanitization.
Remediation
References
https://github.com/bruno-robert/window-control/commit/075c854534a749d887655a906759f5a7eee95173
https://github.com/bruno-robert/window-control/releases/tag/v1.4.5
https://security.snyk.io/vuln/SNYK-JS-WINDOWCONTROL-3186345
Related Vulnerabilities
CVE-2021-3137 Vulnerability in maven package org.xwiki.commons:xwiki-commons
CVE-2020-15095 Vulnerability in maven package org.webjars.bower:npm
CVE-2023-32695 Vulnerability in maven package org.webjars.npm:socket.io-parser
CVE-2020-28440 Vulnerability in npm package corenlp-js-interface
CVE-2018-11786 Vulnerability in maven package org.apache.karaf.shell:org.apache.karaf.shell.core