lifion-verify-dependencies through 1.1.0 is vulnerable to OS command injection via a crafted dependency name on the scanned project's package.json file.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-34078.json"