Description
All versions of the package sketchsvg are vulnerable to Arbitrary Code Injection when invoking shell.exec without sanitization nor parametrization while concatenating the current directory as part of the command string.
Remediation
References
https://github.com/eBay/SketchSVG/blob/dd1036648f0f320a3187ef79d506b676b9eb87a6/lib/index.js%23L115
https://github.com/eBay/SketchSVG/blob/dd1036648f0f320a3187ef79d506b676b9eb87a6/lib/index.js%23L64
https://security.snyk.io/vuln/SNYK-JS-SKETCHSVG-3167969
Related Vulnerabilities
CVE-2021-31712 Vulnerability in npm package react-draft-wysiwyg
CVE-2020-27219 Vulnerability in maven package org.eclipse.hawkbit:hawkbit-update-server
CVE-2021-23673 Vulnerability in npm package pekeupload
CVE-2023-23850 Vulnerability in maven package org.jenkins-ci.plugins:synopsys-coverity
CVE-2023-36478 Vulnerability in maven package org.eclipse.jetty:jetty-http