Description
Mistral npm @mistralai/mistralai, @mistralai/mistralai-azure, @mistralai/mistralai-gcp were compromised by a supply chain attack related to the TanStack security incident. An automated worm associated with the attack led to compromised npm package versions being published.
Recommendation
No fix is available yet. Followings are affected versions:
**= 2.2.4 = 2.2.3 = 2.2.2**
References
Could your website be exposed too?
SmartScanner can check your website for Broken dropper in @mistralai/mistralai, @mistralai/mistralai-azure, @mistralai/mistralai-gcp - @mistralai/mistralai and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Broken dropper in @mistralai/mistralai, @mistralai/mistralai-azure, @mistralai/mistralai-gcp - Vulnerability
- Broken dropper in @mistralai/mistralai, @mistralai/mistralai-azure, @mistralai/mistralai-gcp - @mistralai/mistralai-azure - Vulnerability
- Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability - CVE-2024-35255
- SvelteKit: Prototype pollution in file input deletion path in remote-function forms - Vulnerability


