Description
pixl-class prior to 1.0.3 allows execution of arbitrary commands. The members argument of the create function can be controlled by users without any sanitization.
Remediation
References
https://github.com/jhuckaby/pixl-class/commit/47677a3638e3583e42f3a05cc7f0b30293d2acc8%2C
https://snyk.io/vuln/SNYK-JS-PIXLCLASS-564968
https://github.com/jhuckaby/pixl-class/commit/47677a3638e3583e42f3a05cc7f0b30293d2acc8
Related Vulnerabilities
CVE-2023-34104 Vulnerability in maven package org.webjars.npm:fast-xml-parser
CVE-2018-11039 Vulnerability in maven package org.springframework:spring-web
CVE-2023-29014 Vulnerability in maven package io.goobi.viewer:viewer-core
CVE-2022-41940 Vulnerability in maven package org.webjars.bower:engine.io
CVE-2022-25848 Vulnerability in npm package static-dev-server