All versions of the package vagrant.js are vulnerable to Command Injection via the boxAdd function due to improper input sanitization.
vagrant.js project vagrant.js