CVE-2020-7629: OS Command Injection in install-package

Severity: Critical

CVSS Score: 9.8

install-package through 0.4.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the options argument.