All the vulnerabilities related to the version 0.4.0 of the package
Command Injection in lodash
lodash
versions prior to 4.17.21 are vulnerable to Command Injection via the template function.
Uncontrolled Resource Consumption in trim-newlines
@rkesters/gnuplot is an easy to use node module to draw charts using gnuplot and ps2pdf. The trim-newlines package before 3.0.1 and 4.x before 4.0.1 for Node.js has an issue related to regular expression denial-of-service (ReDoS) for the .end()
method.
Prototype Pollution in node.extend
Versions of node.extend
before 1.1.7 or 2.0.1 are vulnerable to prototype pollution.
Update to version 1.1.7, 2.0.1 or later.