VDB
Sign up
HIGH8.3

GHSA-jvf4-g24p-2qgw

Arbitrary Code Execution in shiba

Details

All versions of package shiba are vulnerable to Arbitrary Code Execution due to the default usage of the function `load()` of the package js-yaml instead of its secure replacement , `safeLoad()`.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/shiba
Introduced in: 0

No fixed version published yet for shiba (npm). Pin to a known-safe version or switch to an alternative.

References