endoplasmic / google-assistant

A node.js implementation of the Google Assistant SDK
MIT License
283 stars 75 forks source link

vulnerability: Prototype pollution in node-forge #87

Closed fcastilloec closed 3 years ago

fcastilloec commented 4 years ago

For a while now, I've been getting messages related to https://npmjs.com/advisories/1561 I don't know if this might not be an easy fix, given that the offending library is a dependency of a dependency. The path for the problem is: google-assistant > google-auth-library > gtoken > google-p12-pem > node-forge