Description
gulp-scss-lint through 1.0.0 allows execution of arbitrary commands. It is possible to inject arbitrary commands to the "exec" function located in "src/command.js" via the provided options.
Remediation
References
https://snyk.io/vuln/SNYK-JS-GULPSCSSLINT-560114
Related Vulnerabilities
CVE-2020-28196 Vulnerability in npm package node-krb5
CVE-2023-39013 Vulnerability in maven package no.priv.garshol.duke:duke
CVE-2020-7625 Vulnerability in npm package op-browser
CVE-2021-44908 Vulnerability in npm package sails
CVE-2024-36401 Vulnerability in maven package org.geoserver.web:gs-web-app