Description
compass-compile through 0.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via tha options argument.
Remediation
References
https://github.com/quaertym/compass-compile/blob/master/lib/compass.js#L25
https://snyk.io/vuln/SNYK-JS-COMPASSCOMPILE-564429
Related Vulnerabilities
CVE-2020-6858 Vulnerability in maven package com.hotels.styx:styx-api
CVE-2021-32643 Vulnerability in maven package org.http4s:http4s-core
CVE-2023-2479 Vulnerability in npm package appium-desktop
CVE-2022-21169 Vulnerability in npm package express-xss-sanitizer
CVE-2023-37942 Vulnerability in maven package org.jenkins-ci.plugins:external-monitor-job