All versions of package theme-core are vulnerable to Command Injection via the lib/utils.js file, which is required by main entry of the package. PoC: var a =require(“theme-core”); a.utils.sh(“touch JHU”)
Dedicated Forum to help removing adware, malware, spyware, ransomware, trojans, viruses and more!
More Stories
CVE-2021-25348 (internet)
CVE-2021-25341 (s_assistant)
CVE-2021-25829 (document_server)