VDB
Sign up
CRITICAL9.8

GHSA-cf4h-3jhx-xvhq

Arbitrary Code Execution in underscore

Quick fix

GHSA-cf4h-3jhx-xvhq — underscore: upgrade to the fixed version with the command below.

npm install underscore@1.12.1

Details

The package `underscore` from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Execution via the template function, particularly when a variable property is passed as an argument as it is not sanitized.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/underscore
Introduced in: 1.3.2Fixed in: 1.12.1
Fixnpm install underscore@1.12.1

References