Product
The better-npm-audit package is vulnerable to arbitrary command injection via improper sanitization of the --registry command-line argument when passed to a shell execution context.