This affects the package node-notifier before 9.0.0. It allows an attacker to run arbitrary commands on Linux machines due to the options params not being sanitised when being passed an array.
{
"source": "CPE_FIELD",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "8.0.1"
}
],
"cpe": "cpe:2.3:a:node-notifier_project:node-notifier:*:*:*:*:*:node.js:*:*"
}