Loading vulnerability details…
CVSS v3.1
6.9
EPSS
0.40%
Published
Mar 6, 2023
Modified
Mar 5, 2025
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
All versions of the package sketchsvg are vulnerable to Arbitrary Code Injection when invoking shell.exec without sanitization nor parametrization while concatenating the current directory as part of the command string.
CVSS Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:LWeaknesses (CWE)
Affected Products (1)
References (6)