Description
gulp-scss-lint through 1.0.0 allows execution of arbitrary commands. It is possible to inject arbitrary commands to the "exec" function located in "src/command.js" via the provided options.
Remediation
References
https://snyk.io/vuln/SNYK-JS-GULPSCSSLINT-560114
Related Vulnerabilities
CVE-2020-7715 Vulnerability in npm package deep-get-set
CVE-2020-36518 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2020-7674 Vulnerability in npm package access-policy
CVE-2023-46498 Vulnerability in npm package @evershop/evershop
CVE-2021-38294 Vulnerability in maven package org.apache.storm:storm-server