Description
compass-compile through 0.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via tha options argument.
Remediation
References
https://github.com/quaertym/compass-compile/blob/master/lib/compass.js#L25
https://snyk.io/vuln/SNYK-JS-COMPASSCOMPILE-564429
Related Vulnerabilities
CVE-2022-39382 Vulnerability in npm package @keystone-6/core
CVE-2023-36820 Vulnerability in maven package io.micronaut.security:micronaut-security-oauth2
CVE-2023-26476 Vulnerability in maven package org.xwiki.platform:xwiki-platform-livetable-ui
CVE-2022-23059 Vulnerability in maven package com.shopizer:sm-shop-model