pahen / madge

Create graphs from your CommonJS, AMD or ES6 module dependencies
MIT License
8.71k stars 312 forks source link

Package impacting the security issue because of requirejs use #425

Open vtulse opened 3 weeks ago

vtulse commented 3 weeks ago

https://github.com/requirejs/r.js/issues/1015 Medium severity requirejs Prototype Pollution VULNERABILITY CWE-1321OPEN THIS LINK IN A NEW TAB CVSS 6.5OPEN THIS LINK IN A NEW TAB MEDIUM SNYK-JS-REQUIREJS-5416713OPEN THIS LINK IN A NEW TAB SCORE 432 Introduced through madge@7.0.0 Exploit maturity PROOF OF CONCEPT Show less detail Detailed paths Introduced through: cshs@0.1.0 › madge@7.0.0 › dependency-tree@10.0.9 › filing-cabinet@4.2.0 › module-lookup-amd@8.0.5 › requirejs@2.3.6 Fix: No remediation path available.