Junglewise Threat Intelligence

CVE-2020-7635: compass-compile command injection in options argument

CVE-2020-7635 · Severity: low · CVSS 3.1 · Published 2021-12-09

Vendors: npm.

Executive brief

compass-compile is a Node.js wrapper for the Compass CSS authoring framework. The library fails to properly validate user-supplied options, allowing attackers to inject arbitrary shell commands that execute on the system with the privileges of the Node.js process. This could lead to complete system compromise, data theft, or deployment of malware.

Technical details

The vulnerability is a command injection flaw (CWE-74) in compass-compile versions through 0.0.1, where the options argument passed to the compile() method is not properly sanitized before being passed to shell execution. An attacker who can control the options parameter can inject shell metacharacters and arbitrary commands. The attack vector is network-adjacent or local depending on how the application exposes the compass-compile functionality. No authentication is required if the function is exposed via an API or web interface. Successful exploitation allows remote code execution with the privilege level of the Node.js process.

Affected products

  • quaertym compass-compile through 0.0.1

Timeline

  • 2020-04-06: disclosed
  • 2021-12-09: advisory

References