CVE-2020-28447: xopen is vulnerable to OS Command Injection in Exported Function xopen(filepath)

Severity: Critical

CVSS Score: 9.8

This affects all versions of package xopen. The injection point is located in line 14 in index.js in the exported function xopen(filepath)