Product
The pickem npm package fails to sanitize item text labels, allowing attackers to perform terminal injection via OSC 52 clipboard writes or UI spoofing.