VYPR
Critical severityNVD Advisory· Published Mar 15, 2020· Updated Aug 4, 2024

CVE-2020-7601

CVE-2020-7601

Description

Command injection in gulp-scss-lint allows arbitrary command execution via crafted options passed to the exec function.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Command injection in gulp-scss-lint allows arbitrary command execution via crafted options passed to the exec function.

Vulnerability

Overview

The gulp-scss-lint package through version 1.0.0 is vulnerable to command injection. The flaw resides in the src/command.js file, where user-controlled options are passed unsafely to the exec function without proper sanitization or validation. This allows an attacker to inject arbitrary shell commands through specially crafted input provided to the plugin's options.

Exploitation

To exploit this vulnerability, an attacker can supply a malicious src option as demonstrated in a proof-of-concept from the JHU System Security Lab [1][2]. When the package processes this option, it passes the injected string directly to exec, enabling execution of arbitrary system commands. No authentication or special privileges are required; the attacker only needs to control the options passed to gulp-scss-lint.

Impact

Successful exploitation allows an attacker to execute arbitrary commands on the system running the vulnerable gulp-scss-lint version. This can lead to severe consequences, including data exfiltration, malware installation, or full system compromise, depending on the privileges of the process executing the package.

Mitigation

A fix has been pushed to the master branch of the repository but was not yet published in a release as of disclosure [2]. Users are advised to avoid using the vulnerable version (1.0.0 or earlier) and monitor the package for an official patched release. No workaround is available other than not passing untrusted input to the options.

AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
gulp-scss-lintnpm
<= 1.0.0

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.