WalletConnect / walletconnect-utils

Javascript Utilities for WalletConnect
MIT License
63 stars 56 forks source link

Dangerous 3rd party package #180

Open rafinskipg opened 1 month ago

rafinskipg commented 1 month ago

Describe the bug Thers a dependency of wallet connect called untun that seems to be able to execute arbitrary code. Which can be a high security risk.

Please, evaluate the risk

The dependency path is : walletconnect -> unstorage -> listhen -> untun

image

https://github.com/wevm/wagmi/issues/4127

linear[bot] commented 1 month ago

CR-482 Dangerous 3rd party package