GHSA-795w-7426-m94j, CVE-2021-33360
npm/@stoqey/gnuplot
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
An issue found in Stoqey gnuplot v.0.0.3 and earlier allows attackers to execute arbitrary code via the src/index.ts, plotCallack, child_process, and/or filePath parameter(s).
All versions up to 0.0.3
Unfortunately, there is no solution available yet.
2023-03-13
source |