Description
gulp-styledocco through 0.0.3 allows execution of arbitrary commands. The argument 'options' of the exports function in 'index.js' can be controlled by users without any sanitization.
Remediation
References
https://snyk.io/vuln/SNYK-JS-GULPSTYLEDOCCO-560126
Related Vulnerabilities
CVE-2020-28277 Vulnerability in maven package org.webjars.npm:dset
CVE-2018-3753 Vulnerability in npm package merge-objects
CVE-2020-7635 Vulnerability in npm package compass-compile
CVE-2019-16303 Vulnerability in npm package generator-jhipster
CVE-2023-22665 Vulnerability in maven package org.apache.jena:jena-arq