VDB
Sign up
CRITICAL9.8

GHSA-w5pw-gmcw-rfc8

squirrelly Code Injection vulnerability

Quick fix

GHSA-w5pw-gmcw-rfc8 — squirrelly: upgrade to the fixed version with the command below.

npm install squirrelly@9.1.0

Details

squirrellyjs squirrelly v9.0.0 was discovered to contain a code injection vulnerability via the component `options.varName`. The issue was fixed in version 9.1.0.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/squirrelly
Introduced in: 9.0.0Fixed in: 9.1.0
Fixnpm install squirrelly@9.1.0

References