Description
compass-compile through 0.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via tha options argument.
Remediation
References
https://github.com/quaertym/compass-compile/blob/master/lib/compass.js#L25
https://snyk.io/vuln/SNYK-JS-COMPASSCOMPILE-564429
Related Vulnerabilities
CVE-2019-20920 Vulnerability in npm package handlebars
CVE-2020-7613 Vulnerability in npm package clamscan
CVE-2021-21617 Vulnerability in maven package org.jenkins-ci.plugins: configurationslicing
CVE-2023-25569 Vulnerability in maven package com.ctrip.framework.apollo:apollo
CVE-2022-31108 Vulnerability in maven package org.webjars.npm:mermaid