create-react-app icon indicating copy to clipboard operation
create-react-app copied to clipboard

Critical Security Vulnerability in @babel/[email protected]

Open AnupSingh97 opened this issue 2 years ago • 4 comments

Describe the bug

[email protected] is using @babel/[email protected] which has a critical vulnerability and was reported by Synk.

Introduced through: [email protected] › @babel/[email protected] › @babel/[email protected] Introduced through: [email protected] › @babel/[email protected] › @babel/[email protected] › @babel/[email protected] Introduced through: [email protected][email protected] › @jest/[email protected][email protected] › @jest/[email protected][email protected][email protected] › @babel/[email protected]

The package @babel/[email protected] used in [email protected] has a critical security vulnerability reported by Synk. This vulnerability is introduced through multiple dependencies, including @babel/[email protected], @babel/[email protected], and indirectly through Jest dependencies ([email protected], @jest/[email protected], [email protected], @jest/[email protected], [email protected], [email protected]).

Vulnerability Details:

Vulnerable Package: @babel/traverse Vulnerable Version: 7.22.8 Affected Dependencies: [email protected] @babel/[email protected] @babel/[email protected] [email protected] @jest/[email protected] [email protected] @jest/[email protected] [email protected] [email protected]

Recommended Fix: Update the @babel/traverse package to the latest non-vulnerable version.

AnupSingh97 avatar Dec 07 '23 07:12 AnupSingh97

up

kevingio-julo avatar Dec 31 '23 09:12 kevingio-julo

+1

jjanczur avatar May 08 '24 11:05 jjanczur