npm›djv›CVE-2020-284649.8 CRITICALCommand InjectionBy controlling the schema file, an attacker can run arbitrary JavaScript code on the victim machine.