Description
All versions of the package vagrant.js are vulnerable to Command Injection via the boxAdd function due to improper input sanitization.
Remediation
References
https://security.snyk.io/vuln/SNYK-JS-VAGRANTJS-3175614
Related Vulnerabilities
CVE-2019-14863 Vulnerability in npm package angular
CVE-2020-2132 Vulnerability in maven package com.parasoft:environment-manager
CVE-2019-10219 Vulnerability in maven package org.hibernate:hibernate-validator
CVE-2022-43434 Vulnerability in maven package io.jenkins.plugins:neuvector-vulnerability-scanner