jubalm / grunt-fontello

grunt task for downloading fonts from fontello.com
MIT License
45 stars 25 forks source link

npm vulnerability #48

Open pdrittenhouse opened 4 years ago

pdrittenhouse commented 4 years ago

High Arbitrary File Overwrite
Package fstream
Patched in >=1.0.12
Dependency of grunt-fontello [dev]
Path grunt-fontello > unzip > fstream
More info https://npmjs.com/advisories/886