Description
All versions of the package vagrant.js are vulnerable to Command Injection via the boxAdd function due to improper input sanitization.
Remediation
References
https://security.snyk.io/vuln/SNYK-JS-VAGRANTJS-3175614
Related Vulnerabilities
CVE-2023-26136 Vulnerability in npm package tough-cookie
CVE-2020-2252 Vulnerability in maven package org.jenkins-ci.plugins:mailer
CVE-2019-10398 Vulnerability in maven package org.jenkins-ci.plugins:beaker-builder
CVE-2022-1330 Vulnerability in npm package fullpage.js
CVE-2023-46654 Vulnerability in maven package org.jenkins-ci.plugins:electricflow