CVE-2020-28464
npm/djv
Command Injection
By controlling the schema file, an attacker can run arbitrary JavaScript code on the victim machine.
All versions before 2.1.4
Upgrade to version 2.1.4 or above.
2021-01-08