CRITICAL9.8
GHSA-g7mq-rfj2-25wq
Code Injection in total4
Quick fix
GHSA-g7mq-rfj2-25wq — total4: upgrade to the fixed version with the command below.
npm install total4@0.0.43Details
The package total4 before 0.0.43 are vulnerable to Arbitrary Code Execution via the `U.set()` and `U.get()` functions.
Are you affected?
Enter the version of the package you're using.