VDB
Sign up
CRITICAL9.8

GHSA-mh6f-8j2x-4483

Critical severity vulnerability that affects event-stream and flatmap-stream

Quick fix

GHSA-mh6f-8j2x-4483 — event-stream: upgrade to the fixed version with the command below.

npm install event-stream@4.0.0

Details

The NPM package `flatmap-stream` is considered malicious. A malicious actor added this package as a dependency to the NPM `event-stream` package in version `3.3.6`. Users of `event-stream` are encouraged to downgrade to the last non-malicious version, `3.3.4`, or upgrade to the latest 4.x version.

Users of `flatmap-stream` are encouraged to remove the dependency entirely.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/event-stream
Introduced in: 3.3.6Fixed in: 4.0.0
Fixnpm install event-stream@4.0.0
npm/flatmap-stream
Introduced in: 0

No fixed version published yet for flatmap-stream (npm). Pin to a known-safe version or switch to an alternative.

References