Junglewise Threat Intelligence

CVE-2021-32830: Diez generation command injection in locateFont

CVE-2021-32830 · Severity: low · CVSS 3.1 · Published 2021-09-02

Vendors: npm.

Executive brief

@diez/generation is an npm package used to generate design token code from Diez design systems. A command injection vulnerability in the locateFont method allows arbitrary code execution if a client application passes untrusted input to this method. This could enable attackers to execute arbitrary commands on developers' machines or build systems that use the library.

Technical details

The @diez/generation npm package contains a command injection vulnerability (CWE-77, CWE-78) in the locateFont method. The vulnerability arises from improper sanitization of user-supplied input when constructing shell commands. An attacker who can influence the input to locateFont with untrusted data can inject arbitrary shell commands. While all versions up to and including 10.6.0 are affected, the attack requires that a client application explicitly call the vulnerable method with untrusted input, requiring developer-level integration of the library. No patch has been released as of the advisory date.

Affected products

  • Diez @diez/generation all versions up to 10.6.0

Timeline

  • 2021-09-02: disclosed
  • 2021-08-17: advisory: NVD publication date

References