This affects the package total.js before 3.4.7. The issue occurs in the image.pipe and functions. The type parameter is used to build the command that is then executed using child_process.spawn. The issue occurs because child_process.spawn is called with the option shell set to true and because the type parameter is not properly sanitized.

