CVE-2020-7614: OS Command Injection
(updated )
npm-programmatic is vulnerable to Command Injection. The packages and option properties are concatenated together without any validation and are used by the exec
function directly.
References
Detect and mitigate CVE-2020-7614 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →