Description
gulp-scss-lint through 1.0.0 allows execution of arbitrary commands. It is possible to inject arbitrary commands to the "exec" function located in "src/command.js" via the provided options.
Remediation
References
https://snyk.io/vuln/SNYK-JS-GULPSCSSLINT-560114
Related Vulnerabilities
CVE-2019-1010266 Vulnerability in maven package org.webjars.bowergithub.lodash:lodash
CVE-2022-24376 Vulnerability in npm package git-promise
CVE-2022-39322 Vulnerability in npm package @keystone-6/core
CVE-2021-21430 Vulnerability in maven package org.openapitools:openapi-generator-project
CVE-2021-23356 Vulnerability in npm package kill-process-by-name