Description
All versions of the package vagrant.js are vulnerable to Command Injection via the boxAdd function due to improper input sanitization.
Remediation
References
https://security.snyk.io/vuln/SNYK-JS-VAGRANTJS-3175614
Related Vulnerabilities
CVE-2020-7645 Vulnerability in npm package chrome-launcher
CVE-2016-10525 Vulnerability in npm package hapi-auth-jwt2
CVE-2020-9296 Vulnerability in maven package com.netflix.conductor:conductor-core
CVE-2023-26486 Vulnerability in maven package org.webjars.npm:vega-functions
CVE-2021-37695 Vulnerability in maven package org.webjars.bowergithub.ckeditor:ckeditor4