Junglewise Threat Intelligence

CVE-2020-7782: krzysztof-o spritesheet-js command injection in generator.js

CVE-2020-7782 · Severity: low · CVSS 3.1 · Published 2021-04-13

Vendors: npm.

Executive brief

spritesheet-js is a tool used by developers to combine multiple images into a single file (a spritesheet) to improve website and application performance. A security flaw in this tool allows an attacker to execute unauthorized commands on the system where the tool is running. This could lead to a complete takeover of the affected server, theft of sensitive data, or disruption of services.

Technical details

All versions of the npm package spritesheet-js are vulnerable to OS command injection. The vulnerability stems from the library's reliance on a vulnerable version of the 'platform-command' package. Specifically, the injection point is located in 'lib/generator.js' at line 32, which is triggered through the main entry point of the package when processing certain configuration options like 'scale'. An attacker can provide specially crafted input that escapes the intended command context to execute arbitrary shell commands with the privileges of the Node.js process. As of the latest advisory, there is no known fixed version for this package.

Affected products

  • krzysztof-o spritesheet-js <= 1.2.6

Timeline

  • 2020-12-04: disclosed: Vulnerability first disclosed to Snyk
  • 2021-02-08: advisory: NVD published the CVE record
  • 2021-04-13: advisory: GitHub Advisory published

References