Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

graphql-let has critical vulnerabilities #183

Open
adanbaiquality opened this issue Oct 29, 2024 · 0 comments
Open

graphql-let has critical vulnerabilities #183

adanbaiquality opened this issue Oct 29, 2024 · 0 comments

Comments

@adanbaiquality
Copy link

Result of npm audit, after trying 'npm audit fix':

@babel/traverse <7.23.2
Severity: critical
Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious code - GHSA-67hx-6x53-jw92
fix available via npm audit fix
node_modules/graphql-let/node_modules/@babel/traverse

loader-utils 2.0.0 - 2.0.3
Severity: critical
Prototype pollution in webpack loader-utils - GHSA-76p3-8jx3-jpfq
loader-utils is vulnerable to Regular Expression Denial of Service (ReDoS) via url variable - GHSA-3rfm-jhwj-7488
loader-utils is vulnerable to Regular Expression Denial of Service (ReDoS) - GHSA-hhq3-ff78-jv3g
fix available via npm audit fix --force
Will install [email protected], which is a breaking change
node_modules/graphql-let/node_modules/loader-utils
graphql-let >=0.18.5
Depends on vulnerable versions of @babel/traverse
Depends on vulnerable versions of loader-utils
Depends on vulnerable versions of minimist
node_modules/graphql-let

minimist 1.0.0 - 1.2.5
Severity: critical
Prototype Pollution in minimist - GHSA-xvch-5gv4-984h
fix available via npm audit fix
node_modules/graphql-let/node_modules/minimist

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant