Description
The Gatsby framework prior to versions 4.25.7 and 5.9.1 contain a Local File Inclusion vulnerability in the __file-code-frame
and __original-stack-frame
paths, exposed when running the Gatsby develop server (gatsby develop
).
Recommendation
Update the gatsby
package to the latest compatible version. Followings are version details:
Affected version(s): **>= 5.0.0, <= 5.9.0 <= 4.25.6** Patched version(s): **5.9.1 4.25.7**
References
Related Issues
- @digitalocean/do-markdownit has Type Confusion vulnerability - CVE-2025-59717
- node-opcua-alarm-condition prototype pollution vulnerability - CVE-2024-57086
- Parse Server before v3.4.1 vulnerable to Denial of Service - CVE-2019-1020012
- axios Inefficient Regular Expression Complexity vulnerability - CVE-2021-3749
- Tags:
- npm
- gatsby
Anything's wrong? Let us know Last updated on November 11, 2023