-
-
Notifications
You must be signed in to change notification settings - Fork 1.6k
npm audit failed (10.0/bugfixes) #23771
Copy link
Copy link
Open
Description
# npm audit report
lodash <=4.17.23
Severity: high
lodash vulnerable to Code Injection via `_.template` imports key names - https://github.com/advisories/GHSA-r5fr-rjxr-66jc
lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit` - https://github.com/advisories/GHSA-f23m-r3pf-42rh
fix available via `npm audit fix`
node_modules/lodash
chartist-plugin-tooltips-updated 0.1.4
Depends on vulnerable versions of lodash
node_modules/chartist-plugin-tooltips-updated
2 high severity vulnerabilities
To address all issues, run:
npm audit fix
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels