The dashboard component of StackLift LocalStack 0.12.6 allows attackers to inject arbitrary shell commands via the functionName parameter.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-32090.json"