A command injection vulnerability affects the package image-tiler before version 2.0.2. References https://nvd.nist.gov/vuln/detail/CVE-2020-28451 https://github.com/MrP/image-tiler/commit/f4a0b13a4bf43655fc4013e04bbceaf77aecbeb8 https://security.snyk.io/vuln/SNYK-JS-IMAGETILER-1051029 https://github.com/advisories/GHSA-mrxv-pr4h-963q