{"id":"GHSA-vm5j-vqr6-v7v8","summary":"OS Command Injection in pixl-class","details":"pixl-class prior to 1.0.3 allows execution of arbitrary commands. The members argument of the create function can be controlled by users without any sanitization.","aliases":["CVE-2020-7640","SNYK-JS-PIXLCLASS-564968"],"modified":"2026-05-07T04:57:15.121319873Z","published":"2021-12-10T20:04:56Z","database_specific":{"nvd_published_at":"2020-04-27T22:15:00Z","cwe_ids":["CWE-78"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2021-05-25T20:40:19Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-7640"},{"type":"WEB","url":"https://github.com/jhuckaby/pixl-class/commit/47677a3638e3583e42f3a05cc7f0b30293d2acc8"},{"type":"WEB","url":"https://github.com/jhuckaby/pixl-class/commit/47677a3638e3583e42f3a05cc7f0b30293d2acc8,"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-PIXLCLASS-564968"}],"affected":[{"package":{"name":"pixl-class","ecosystem":"npm","purl":"pkg:npm/pixl-class"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.0.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/12/GHSA-vm5j-vqr6-v7v8/GHSA-vm5j-vqr6-v7v8.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}