LayerXcom / vyper-remix

Remix Vyper Plugin
Apache License 2.0
17 stars 36 forks source link

`merge` package `v1.2.0` has vulnerability #70

Closed yudetamago closed 5 years ago

yudetamago commented 5 years ago

https://github.com/LayerXcom/vyper-remix/blob/8b593d7d7a1e288955952ad8a841265ba8a28e57/package-lock.json#L3865 exec-sh package 0.2.2 requires merge package 1.2.0.

merge package 1.2.0 has CVE-2018-16469 ( https://nvd.nist.gov/vuln/detail/CVE-2018-16469 ) vulnerability.

To solve this, it is needed to upgrade exec-sh.