TooTallNate / proxy-agents

Node.js HTTP Proxy Agents Monorepo
https://proxy-agents.n8.io
919 stars 238 forks source link

Legacy word-wrap dependency causing ReDoS vulnevarilibies #201

Closed jose-p-rivera closed 1 year ago

jose-p-rivera commented 1 year ago

image

this is affecting multiple packages that depend on proxy-agents such as puppeteer.

TooTallNate commented 1 year ago

Tracking possible fix here, but seems like the package is not being maintained.

dikirill commented 1 year ago

@TooTallNate please update optionator version, it has a fix already.

elrob commented 1 year ago

Are you able to update the escodegen used in degenerator to the latest? I think that will resolve the issue as optionator is no longer in the non-dev dependencies.