Le paquet ng-packagr avant 10.1.1 sont vulnérables à l’injection de commande via l’option styleIncludePaths.
https://github.com/ng-packagr/ng-packagr/commit/bda0fff3443301f252930a73fdc8fb9502de596d
https://github.com/ng-packagr/ng-packagr/commit/bda0fff3443301f252930a73fdc8fb9502de596d
https://snyk.io/vuln/SNYK-JS-NGPACKAGR-1012427
https://snyk.io/vuln/SNYK-JS-NGPACKAGR-1012427
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7735