vscode-js-import
vscode-js-import copied to clipboard
Found Vulnerability in Repository Due to Dependency on 'open' Package
Hello,
I hope this message finds you well. I wanted to bring to your attention an important security concern that I discovered upon cloning the repository.
Upon a thorough review, I identified a vulnerability directly linked to the dependency on the 'open' package. The current version of 'open' used in the repository has known security vulnerabilities that could potentially be exploited.
The specific vulnerability is:
- Vulnerability: Arbitrary Code Injection [Critical Severity]
- Affected Package: [email protected]
- Recommended Action: Upgrade to [email protected]