Description
compass-compile through 0.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via tha options argument.
Remediation
References
https://github.com/quaertym/compass-compile/blob/master/lib/compass.js#L25
https://snyk.io/vuln/SNYK-JS-COMPASSCOMPILE-564429
Related Vulnerabilities
CVE-2018-17960 Vulnerability in maven package org.webjars.npm:ckeditor
CVE-2021-3666 Vulnerability in npm package body-parser-xml
CVE-2020-2296 Vulnerability in maven package org.jenkins-ci.plugins:shared-objects
CVE-2022-24947 Vulnerability in maven package org.apache.jspwiki:jspwiki-main
CVE-2020-13128 Vulnerability in maven package com.googlecode.gwtupload:gwtupload-project