CVE-2019-10799: Compile-Sass Project Compile-Sass
High severity, CVSS 8.2. EPSS: 2.3% chance of exploitation in the next 30 days.
compile-sass prior to 1.0.5 allows execution of arbritary commands. The function "setupCleanupOnExit(cssPath)" within "dist/index.js" is executed as part of the "rm" command without any sanitization.
Affected products
- Compile-Sass Project Compile-Sass: before 1.0.5 (fixed in 1.0.5)
Published 2020-02-24. Last modified 2026-06-17.