1 results (0.001 seconds)

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 1

All versions of the package sketchsvg are vulnerable to Arbitrary Code Injection when invoking shell.exec without sanitization nor parametrization while concatenating the current directory as part of the command string. • https://github.com/eBay/SketchSVG/blob/dd1036648f0f320a3187ef79d506b676b9eb87a6/lib/index.js%23L115 https://github.com/eBay/SketchSVG/blob/dd1036648f0f320a3187ef79d506b676b9eb87a6/lib/index.js%23L64 https://security.snyk.io/vuln/SNYK-JS-SKETCHSVG-3167969 • CWE-94: Improper Control of Generation of Code ('Code Injection') •