CVE-2022-25908: Command Injection in create-choo-electron

Severity: Critical

CVSS Score: 9.8

All versions of the package create-choo-electron are vulnerable to Command Injection via the devInstall function due to improper user-input sanitization.