A command Injection in ps package versions <1.0.0 for Node.js allowed arbitrary commands to be executed when attacker controls the PID.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-16460.json"