Skip to content

"OS Command Injection" critical alert #96

Open
@jasewarner

Description

@jasewarner

I'm using this package (which is great, by the way – thank you!) and I've noticed a critical alert in my repo titled "OS Command Injection":

gulp-scss-lint through 1.0.0 allows execution of arbitrary commands. It is possible to inject arbitrary commands to the "exec" function located in "src/command.js" via the provided options.

Is there a plan in place to fix this problem in a future release?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions