CVE-2020-7794: Command injection in buns

Severity: Critical

CVSS Score: 9.8

This affects all versions of package buns. The injection point is located in line 678 in index file lib/index.js in the exported function install(requestedModule).