Description
gulp-styledocco through 0.0.3 allows execution of arbitrary commands. The argument 'options' of the exports function in 'index.js' can be controlled by users without any sanitization.
Remediation
References
https://snyk.io/vuln/SNYK-JS-GULPSTYLEDOCCO-560126
Related Vulnerabilities
CVE-2022-35915 Vulnerability in npm package @openzeppelin/contracts
CVE-2022-41250 Vulnerability in maven package com.meowlomo.jenkins:scm-httpclient
CVE-2023-26136 Vulnerability in maven package org.webjars.npm:tough-cookie
CVE-2022-23944 Vulnerability in maven package org.apache.shenyu:shenyu-common
CVE-2021-21122 Vulnerability in maven package org.webjars.npm:electron