This affects the package connection-tester before 0.2.1. The injection point is located in line 15 in index.js. Affected versions of this package are vulnerable to Command Injection
{
"cwe_ids": [
"CWE-78"
],
"github_reviewed": true,
"github_reviewed_at": "2020-12-17T18:31:49Z",
"nvd_published_at": "2020-12-16T18:15:00Z",
"severity": "CRITICAL"
}