Description
This affects all versions of package spritesheet-js. It depends on a vulnerable package platform-command. The injection point is located in line 32 in lib/generator.js, which is triggered by main entry of the package.
Remediation
References
https://snyk.io/vuln/SNYK-JS-SPRITESHEETJS-1048333
https://github.com/krzysztof-o/spritesheet.js/blob/master/lib/generator.js%23L32
https://www.npmjs.com/package/spritesheet-js
Related Vulnerabilities
CVE-2017-1000427 Vulnerability in maven package org.webjars.bower:marked
CVE-2020-8141 Vulnerability in maven package org.webjars.bowergithub.olado:dot
CVE-2021-4264 Vulnerability in npm package dustjs-linkedin
CVE-2023-26111 Vulnerability in npm package node-static
CVE-2021-31805 Vulnerability in maven package org.apache.struts:struts2-core