Description
The package ng-packagr before 10.1.1 are vulnerable to Command Injection via the styleIncludePaths option.
Remediation
References
https://snyk.io/vuln/SNYK-JS-NGPACKAGR-1012427
https://github.com/ng-packagr/ng-packagr/commit/bda0fff3443301f252930a73fdc8fb9502de596d
Related Vulnerabilities
CVE-2023-5571 Vulnerability in npm package @vrite/sdk
CVE-2022-22965 Vulnerability in maven package org.springframework:spring-webmvc
CVE-2022-45400 Vulnerability in maven package org.jvnet.hudson.plugins:japex
CVE-2022-23913 Vulnerability in maven package org.apache.activemq:artemis-core-client
CVE-2018-11697 Vulnerability in maven package org.webjars.npm:node-sass