Description
compass-compile through 0.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via tha options argument.
Remediation
References
https://github.com/quaertym/compass-compile/blob/master/lib/compass.js#L25
https://snyk.io/vuln/SNYK-JS-COMPASSCOMPILE-564429
Related Vulnerabilities
CVE-2021-23444 Vulnerability in npm package jointjs
CVE-2021-23358 Vulnerability in maven package org.webjars.npm:underscore
CVE-2022-0512 Vulnerability in npm package url-parse
CVE-2023-36665 Vulnerability in maven package org.webjars.npm:protobufjs
CVE-2022-43426 Vulnerability in maven package io.jenkins.plugins:s3explorer