Codecov npm module before 3.6.2 allows remote attackers to execute arbitrary commands via the "gcov-args" argument.
codecov
{ "last_known_affected_version_range": "<= 3.61" }