VYPR

npm package

sketchsvg

pkg:npm/sketchsvg

Vulnerabilities (1)

  • CVE-2023-26107MedMar 6, 2023
    affected <= 0.0.1

    All versions of the package sketchsvg are vulnerable to Arbitrary Code Injection when invoking shell.exec without sanitization nor parametrization while concatenating the current directory as part of the command string.