CRITICAL9.8
GHSA-w5pw-gmcw-rfc8
squirrelly Code Injection vulnerability
Quick fix
GHSA-w5pw-gmcw-rfc8 — squirrelly: upgrade to the fixed version with the command below.
npm install squirrelly@9.1.0Details
squirrellyjs squirrelly v9.0.0 was discovered to contain a code injection vulnerability via the component `options.varName`. The issue was fixed in version 9.1.0.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-40453[ADVISORY]
- https://github.com/squirrellyjs/squirrelly/pull/262[WEB]
- https://github.com/squirrellyjs/squirrelly/commit/426f930e5ca1501404cd887071e734ec5feb0bcf[WEB]
- https://github.com/squirrellyjs/squirrelly[PACKAGE]
- https://samuzora.com/posts/cve-2024-40453[WEB]