Description
gulp-scss-lint through 1.0.0 allows execution of arbitrary commands. It is possible to inject arbitrary commands to the "exec" function located in "src/command.js" via the provided options.
Remediation
References
https://snyk.io/vuln/SNYK-JS-GULPSCSSLINT-560114
Related Vulnerabilities
CVE-2021-23337 Vulnerability in maven package org.webjars:lodash
CVE-2021-21307 Vulnerability in maven package org.lucee:lucee
CVE-2022-45598 Vulnerability in npm package @joplin/renderer
CVE-2023-50571 Vulnerability in maven package org.jeasy:easy-rules-mvel
CVE-2021-42697 Vulnerability in maven package com.typesafe.akka:akka-http-core