Description
pixl-class prior to 1.0.3 allows execution of arbitrary commands. The members argument of the create function can be controlled by users without any sanitization.
Remediation
References
https://github.com/jhuckaby/pixl-class/commit/47677a3638e3583e42f3a05cc7f0b30293d2acc8
https://github.com/jhuckaby/pixl-class/commit/47677a3638e3583e42f3a05cc7f0b30293d2acc8%2C
https://snyk.io/vuln/SNYK-JS-PIXLCLASS-564968
Related Vulnerabilities
CVE-2021-21316 Vulnerability in npm package less-openui5
CVE-2016-6652 Vulnerability in maven package org.springframework.data:spring-data-jpa
CVE-2022-41965 Vulnerability in maven package org.opencastproject:opencast-engage-paella-player
CVE-2021-26539 Vulnerability in npm package sanitize-html
CVE-2011-0013 Vulnerability in maven package org.apache.tomcat:tomcat-catalina