node-key-sender through 1.0.11 is vulnerable to Command Injection. It allows execution of arbitrary commands via the βarrParamsβ argument in the βexecute()β function.
https://github.com/garimpeiro-it/node-key-sender/blob/master/key-sender.js#L117
https://snyk.io/vuln/SNYK-JS-NODEKEYSENDER-564261
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7627