CRITICAL9.6
GHSA-mcvg-g9wx-v5vx
Valine code injection vulnerability
Quick fix
GHSA-mcvg-g9wx-v5vx — valine: upgrade to the fixed version with the command below.
npm install valine@1.5.0Details
Valine was discovered to contain a remote code execution (RCE) vulnerability which allows attackers to execute arbitrary code via a crafted POST request.
Are you affected?
Enter the version of the package you're using.