node-key-sender through 1.0.11 is vulnerable to Command Injection. It allows execution of arbitrary commands via the 'arrParams' argument in the 'execute()' function.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| node-key-sender(npm) | 0 | N/A | N/A |
CVSS Metrics