Description
Faker.js helps users create large amounts of data for testing and development. The maintainer deliberately removed the functional code from this package. This appears to be a purposeful and successful attempt to make the package unusable. This is related to the colors.js CVE-2021-23567.
Recommendation
No fix is available yet. Followings are affected versions:
- = 6.6.6
References
Related Issues
- Valine code injection vulnerability - CVE-2022-38545
- Remote code execution in Handlebars.js - Vulnerability
- Sandbox Bypass Leading to Arbitrary Code Execution in constantinople - Vulnerability
- HTML comments vulnerability allowing to execute JavaScript code - CVE-2021-41165
You might also like:
- Tags:
- npm
- faker
Anything's wrong? Let us know Last updated on January 11, 2023


