schwarzdavid / bootstrap-email

MIT License
27 stars 11 forks source link

Vulnerability in npm audit #36

Open emobs opened 1 year ago

emobs commented 1 year ago

Hello,

I get this critical vulnerability reported by npm audit after installing the bootstrap-email package:

Critical ejs template injection vulnerability Package ejs Patched in >=3.1.7 Dependency of bootstrap-email Path bootstrap-email > ejs More info https://github.com/advisories/GHSA-phwq-j96m-2c2q

I got EJS updated to the latest version (3.1.9), but also tried 3.1.7 without success.

Can you help me to solve this issue?

Thanks for your reply and help in advance!

knopkem commented 9 months ago

https://www.npmjs.com/package/@knopkem/bootstrap-email