npm›morgan›CVE-2019-54139.8 CRITICALCommand InjectionAn attacker can use the format parameter to inject arbitrary commands in the npm package morgan.