MEDIUM6.5
GHSA-2gmp-34j9-fqjm
Replicator deserializes untrusted user input
Details
An unauthenticated Remote Code Execution (RCE) vulnerability exists in applications that use the Replicator node package manager (npm) version 1.0.5 to deserialize untrusted user input and execute the resulting object.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/replicator
Introduced in:
0No fixed version published yet for replicator (npm). Pin to a known-safe version or switch to an alternative.