The samba-client package prior to 4.0.0 for Node.js allows command injection because of the use of process.exec.
samba-client project samba-client