这是indexloc提供的服务,不要输入任何密码
Skip to content

Dependency Async vulnerable to Prototype Pollution #23

@henrymcl

Description

@henrymcl
# npm audit report

async  <2.6.4
Severity: high
Prototype Pollution in async - https://github.com/advisories/GHSA-fwr7-v2mv-hh25
No fix available
node_modules/async
  express-zip  *
  Depends on vulnerable versions of async
  node_modules/express-zip

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions