Description
All versions of the package sketchsvg are vulnerable to Arbitrary Code Injection when invoking shell.exec without sanitization nor parametrization while concatenating the current directory as part of the command string.
Remediation
References
https://github.com/eBay/SketchSVG/blob/dd1036648f0f320a3187ef79d506b676b9eb87a6/lib/index.js%23L115
https://github.com/eBay/SketchSVG/blob/dd1036648f0f320a3187ef79d506b676b9eb87a6/lib/index.js%23L64
https://security.snyk.io/vuln/SNYK-JS-SKETCHSVG-3167969
Related Vulnerabilities
CVE-2023-37961 Vulnerability in maven package org.jenkins-ci.plugins:assembla-auth
CVE-2021-23377 Vulnerability in npm package onion-oled-js
CVE-2018-16487 Vulnerability in npm package lodash.merge
CVE-2020-6460 Vulnerability in npm package electron
CVE-2018-11695 Vulnerability in maven package org.webjars.npm:node-sass