Skip to content

Moderate Vulnerability in used static-eval version #74

@ekelvin

Description

@ekelvin

Can you please consider upgrading static-eval to version >= 2.0.0 where this vulnerability is patched ?

Moderate Sandbox Breakout / Arbitrary Code Execution
Package static-eval
Patched in >=2.0.0
Dependency of webpack-spritesmith [dev]
Path webpack-spritesmith > spritesmith > pixelsmith >
ndarray-fill > cwise > static-module > static-eval
More info https://nodesecurity.io/advisories/548

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions