A cross-platform Node.js wrapper around the standard Unix computer program, df.
Known vulnerabilities in the node-df package. This does not include vulnerabilities belonging to this package’s dependencies.Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
node-df is a cross-platform Node.js wrapper around the standard Unix computer program (disk free).
Affected versions of this package are vulnerable to Command Injection. The issue occurs because a
PoC by mik317
How to fix Command Injection?
There is no fixed version for