vercel / styled-jsx

Full CSS support for JSX without compromises
http://npmjs.com/styled-jsx
MIT License
7.65k stars 266 forks source link

Security Vulnerability on dependency loader-utils@1.2.3 - CVE-2022-37601 #819

Closed arrudadev closed 1 year ago

arrudadev commented 1 year ago

Do you want to request a feature or report a bug?

Bug.

What is the current behavior?

A security vulnerability has been raised on one of styled-jsx dependency loader-utils@1.2.3

https://avd.aquasec.com/nvd/2022/cve-2022-37601/

https://nvd.nist.gov/vuln/detail/CVE-2022-37601#range-8570977

This issue is fixed in the v1.4.1 and v2.0.3 versions

Environment

styled-jsx - v5.1.0

What is the expected behavior?

Update the loader-utils to v1.4.1.