Here’s the corresponding blog post from the researcher, describing how they discovered the vulnerability: <a href="https://blog.ryotak.me/post/cdnjs-remote-code-execution-en/" rel="nofollow">https://blog.ryotak.me/post/cdnjs-remote-code-execution-en/</a>