All versions of package nuance-gulp-build-common are vulnerable to Command Injection via the index.js file. PoC: /var a = require(«nuance-gulp-build-common») a.run(«touch JHU»)