Skip to content

High level Arbitrary Command Injection vulnerability #7908

Closed
@micheleriso

Description

@micheleriso

Describe the bug

Last version of react-dev-utils requires the library [email protected] that has an high level Arbitrary Command Injection vulnerability https://snyk.io/vuln/npm:open:20180512

Did you try recovering your dependencies?

Yes. I updated to latest versions

Which terms did you search for in User Guide?

Environment

Steps to reproduce

(Write your steps here:)

  1. Npm install react-scripts
  2. npm audit

Expected behavior

(Write what you thought would happen.)

Actual behavior

(Write what happened. Please add screenshots!)

Reproducible demo

(Paste the link to an example project and exact instructions to reproduce the issue.)

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions