Description
All versions of the package sketchsvg are vulnerable to Arbitrary Code Injection when invoking shell.exec without sanitization nor parametrization while concatenating the current directory as part of the command string.
Remediation
References
https://github.com/eBay/SketchSVG/blob/dd1036648f0f320a3187ef79d506b676b9eb87a6/lib/index.js%23L115
https://github.com/eBay/SketchSVG/blob/dd1036648f0f320a3187ef79d506b676b9eb87a6/lib/index.js%23L64
https://security.snyk.io/vuln/SNYK-JS-SKETCHSVG-3167969
Related Vulnerabilities
CVE-2023-46998 Vulnerability in maven package org.webjars.bowergithub.makeusabrew:bootbox
CVE-2020-7793 Vulnerability in npm package ua-parser-js
CVE-2020-7703 Vulnerability in npm package nis-utils
CVE-2019-15903 Vulnerability in npm package dbus
CVE-2020-24855 Vulnerability in npm package @easy-team/easywebpack-cli