Description
compass-compile through 0.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via tha options argument.
Remediation
References
https://github.com/quaertym/compass-compile/blob/master/lib/compass.js#L25
https://snyk.io/vuln/SNYK-JS-COMPASSCOMPILE-564429
Related Vulnerabilities
CVE-2021-39168 Vulnerability in npm package @openzeppelin/contracts-upgradeable
CVE-2017-16175 Vulnerability in npm package ewgaddis.lab6
CVE-2021-33041 Vulnerability in npm package vmd
CVE-2023-28155 Vulnerability in maven package org.webjars.bower:request
CVE-2023-40349 Vulnerability in maven package org.jenkins-ci.plugins:gogs-webhook