pixl-class prior to 1.0.3 allows execution of arbitrary commands. The members argument of the create function can be controlled by users without any sanitization.
{ "github_reviewed": true, "severity": "HIGH", "nvd_published_at": "2020-04-27T22:15:00Z", "cwe_ids": [ "CWE-78" ], "github_reviewed_at": "2021-05-25T20:40:19Z" }