CRITICAL
GHSA-wqgx-4q47-j2w5
Insecure Cryptography Algorithm in parsel
Details
All versions of `parsel` use an insecure cryptography algorithm. The package uses `aes-256-cbc` without integrity checks, which renders the ciphertext vulnerable to bit-flipping attacks.
## Recommendation
The package is deprecated and will not be updated. Consider using an alternative package.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/parsel
Introduced in:
0.0.0No fixed version published yet for parsel (npm). Pin to a known-safe version or switch to an alternative.