cloudsploit icon indicating copy to clipboard operation
cloudsploit copied to clipboard

CVE-2024-21538: HIGH vulnerability in cross-spawn dependency

Open JulesClaussen opened this issue 9 months ago • 0 comments
trafficstars

Hello,

There's a HIGH finding in the package cross-spawn, that is a dependency of quite a few packages (eslint among those). Would it be possible to bump those packages? And eventually setup trivy or other tools to avoid these in the future? Finding: https://avd.aquasec.com/nvd/2024/cve-2024-21538/

Thanks! Jules

JulesClaussen avatar Feb 17 '25 17:02 JulesClaussen