KyleAMathews / cjsx-loader

coffee-react-transform loader module for webpack
53 stars 11 forks source link

cjsx-loader uses a vulnerable version of loader-utils #16

Open dianagiova opened 1 year ago

dianagiova commented 1 year ago

There is a prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils prior to version 2.0.3 via the name variable in parseQuery.js.

Do you plan on updating the loader-utils dependency in your package?