Description
All versions of the package vagrant.js are vulnerable to Command Injection via the boxAdd function due to improper input sanitization.
Remediation
References
https://security.snyk.io/vuln/SNYK-JS-VAGRANTJS-3175614
Related Vulnerabilities
CVE-2022-31367 Vulnerability in npm package @strapi/strapi
CVE-2020-15095 Vulnerability in maven package org.webjars.bower:npm
CVE-2022-2064 Vulnerability in npm package nocodb
CVE-2015-8103 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2021-29459 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web