dns-sync is a sync/blocking dns resolver. If untrusted user input is allowed into the resolve() method then command injection is possible.Referenceshttps://github.com/skoranga/node-dns-sync/issues/5https://nodesecurity.io/advisories/523