Executive brief
SketchSVG is a command-line tool used to convert icon designs from Sketch files into compressed SVG files for web use. The tool contains a vulnerability that allows attackers to execute arbitrary code by manipulating the current directory name when the tool processes files, potentially leading to complete system compromise.
Technical details
SketchSVG invokes shell commands via shell.exec with unsanitized user input, concatenating the current directory path directly into the command string without proper parametrization or escaping (CWE-94: Improper Control of Generation of Code). An attacker can craft a directory name containing shell metacharacters or command injection payloads that will be executed with the privileges of the user running SketchSVG. Attack requires local access and the ability to create or control the directory from which SketchSVG is invoked. All versions of the sketchsvg npm package through at least 0.0.1 are affected. Fixes are available in newer versions.
Affected products
- eBay SketchSVG all versions through 0.0.1
Timeline
- 2023-03-06: disclosed
- 2023-03-07: advisory: GitHub reviewed at 2023-03-07T20:30:33Z