Description
pixl-class prior to 1.0.3 allows execution of arbitrary commands. The members argument of the create function can be controlled by users without any sanitization.
Remediation
References
https://github.com/jhuckaby/pixl-class/commit/47677a3638e3583e42f3a05cc7f0b30293d2acc8%2C
https://snyk.io/vuln/SNYK-JS-PIXLCLASS-564968
https://github.com/jhuckaby/pixl-class/commit/47677a3638e3583e42f3a05cc7f0b30293d2acc8
Related Vulnerabilities
CVE-2020-8570 Vulnerability in maven package io.kubernetes:client-java
CVE-2023-5245 Vulnerability in maven package ml.combust.bundle:bundle-ml_2.12
CVE-2022-39368 Vulnerability in maven package org.eclipse.californium:element-connector
CVE-2022-1274 Vulnerability in maven package org.keycloak:keycloak-services