compile-sass prior to 1.0.5 allows execution of arbritary commands. The function "setupCleanupOnExit(cssPath)" within "dist/index.js" is executed as part of the "rm" command without any sanitization.
{
"severity": "HIGH",
"github_reviewed": true,
"cwe_ids": [
"CWE-78"
],
"github_reviewed_at": "2021-04-08T20:21:56Z",
"nvd_published_at": "2020-02-24T18:15:00Z"
}