https://github.com/afaqurk/linux-dash/blob/master/app/server/index.js#L76 and https://github.com/afaqurk/linux-dash/blob/master/app/server/index.py#L30 are lacking escaping and are vulnerable to command injection