Severity: Critical
CVSS Score: 9.8
This affects all versions of package xopen. The injection point is located in line 14 in index.js in the exported function xopen(filepath)