Vulnerabilities/

squirrelly Code Injection vulnerability

Severity:
High

Description

squirrellyjs squirrelly v9.0.0 was discovered to contain a code injection vulnerability via the component options.varName. The issue was fixed in version 9.1.0.

Recommendation

Update the squirrelly package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
squirrelly
Anything's wrong? Let us know Last updated on August 21, 2024

This issue is available in SmartScanner Professional

See Pricing