Description
pixl-class prior to 1.0.3 allows execution of arbitrary commands. The members argument of the create function can be controlled by users without any sanitization.
Remediation
References
https://github.com/jhuckaby/pixl-class/commit/47677a3638e3583e42f3a05cc7f0b30293d2acc8
https://github.com/jhuckaby/pixl-class/commit/47677a3638e3583e42f3a05cc7f0b30293d2acc8%2C
https://snyk.io/vuln/SNYK-JS-PIXLCLASS-564968
Related Vulnerabilities
CVE-2023-50720 Vulnerability in maven package org.xwiki.platform:xwiki-platform-search-solr-api
CVE-2021-32769 Vulnerability in maven package io.micronaut:micronaut-core
CVE-2023-45133 Vulnerability in maven package org.webjars.npm:babel-traverse
CVE-2017-7661 Vulnerability in maven package org.apache.cxf.fediz:fediz-jetty8
CVE-2021-45457 Vulnerability in maven package org.apache.kylin:kylin-server