CVE-2022-25962: Command injection in vagrant.js

Severity: Critical

CVSS Score: 9.8

All versions of the package vagrant.js are vulnerable to Command Injection via the boxAdd function due to improper input sanitization.