-
-
Notifications
You must be signed in to change notification settings - Fork 3.1k
Open
Labels
Description
trim <0.0.3
Severity: high
Regular Expression Denial of Service in trim - https://github.com/advisories/GHSA-w5p7-h5w8-2hfq
No fix available
node_modules/trim
mdast-util-to-hast <=6.0.2
Depends on vulnerable versions of trim
node_modules/netlify-cms-widget-markdown/node_modules/mdast-util-to-hast
remark-rehype <=5.0.0
Depends on vulnerable versions of mdast-util-to-hast
node_modules/netlify-cms-widget-markdown/node_modules/remark-rehype
remark-parse <=8.0.3
Depends on vulnerable versions of trim
node_modules/netlify-cms-widget-markdown/node_modules/remark-parse
netlify-cms-widget-markdown *
Depends on vulnerable versions of remark-parse
node_modules/netlify-cms-widget-markdown
netlify-cms-app *
Depends on vulnerable versions of netlify-cms-widget-markdown
node_modules/netlify-cms-app
Are there any plans to upgrade these packages? Also reported here: https://snyk.io/test/npm/netlify-cms
mpilnan, tomhermans, PetroPavlenko, MarciD, stevenwilliamson and 5 morejee-rchangethe and jee-r
Metadata
Metadata
Assignees
Labels
Type
Projects
Status
Selected for Development