CRITICAL9.8
GHSA-7q9f-x6rm-qmxr
Command Injection in compass-compile
Details
compass-compile through 0.0.1 is vulnerable to Command Injection. It allows execution of arbitrary commands via the options argument.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/compass-compile
Introduced in:
0No fixed version published yet for compass-compile (npm). Pin to a known-safe version or switch to an alternative.