@cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized --workspace Argument on Windows
A Windows-specific command injection vulnerability exists in @cyclonedx/cyclonedx-npm when the CLI is invoked with the –workspace <value> option. User-supplied –workspace values can be passed to a shell command without proper neutralization on the Windows fallback execution path, enabling attackers to inject arbitrary OS commands. The vulnerability was fixed in version [6.0.0][v6.0.0].