Description
All versions of the package sketchsvg are vulnerable to Arbitrary Code Injection when invoking shell.exec without sanitization nor parametrization while concatenating the current directory as part of the command string.
Remediation
References
https://github.com/eBay/SketchSVG/blob/dd1036648f0f320a3187ef79d506b676b9eb87a6/lib/index.js%23L115
https://github.com/eBay/SketchSVG/blob/dd1036648f0f320a3187ef79d506b676b9eb87a6/lib/index.js%23L64
https://security.snyk.io/vuln/SNYK-JS-SKETCHSVG-3167969
Related Vulnerabilities
CVE-2020-7021 Vulnerability in maven package org.elasticsearch:elasticsearch
CVE-2022-37767 Vulnerability in maven package io.pebbletemplates:pebble
CVE-2020-28490 Vulnerability in npm package async-git
CVE-2021-23446 Vulnerability in npm package handsontable
CVE-2018-1002204 Vulnerability in maven package org.webjars.npm:adm-zip