Описание
OS Command Injection in gulkp-styledocco
gulp-styledocco through 0.0.3 allows execution of arbitrary commands. The argument options of the exports function in index.js can be controlled by users without any sanitization.
Пакеты
Наименование
gulp-styledocco
npm
Затронутые версииВерсия исправления
<= 0.0.3
Отсутствует
Связанные уязвимости
CVSS3: 9.8
nvd
почти 6 лет назад
gulp-styledocco through 0.0.3 allows execution of arbitrary commands. The argument 'options' of the exports function in 'index.js' can be controlled by users without any sanitization.