lmhunterand

Results 114 issues of lmhunterand

**Summary** **Test plan** **Checklist** Please add a `x` inside each checkbox: - [x] I have read the [contribution guidelines](../CONTRIBUTING.md). - [x] Code is formatted via running `yarn format`. - [x]...

**Describe the bug** Web applications hosted on the "developer.paypal.com" domain are affected by a Server Side Request Forgery (SSRF) vulnerability that could allow an attacker to force an application to...

Upgrade ansi-regex to version 5.0.1 or later. For example: ``` ansi-regex@^5.0.1: version "5.0.1" ``` ansi-regex is vulnerable to Inefficient Regular Expression Complexity

The latest possible version that can be installed is ``1.7.2`` because of the following conflicting dependencies: ``` @fec/[email protected] requires [email protected] via a transitive dependency on [email protected] [email protected] requires [email protected] via...

The package terser before 4.8.1, from 5.0.0 and before 5.14.2 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure usage of regular expressions. upgrade terser to version...

``` tar@^4.4.18: version "4.4.18" ``` Arbitrary File Creation, Arbitrary File Overwrite, Arbitrary Code Execution node-tar aims to guarantee that any file whose location would be modified by a symbolic link...

CommonMarker uses ``cmark-gfm`` for rendering [Github Flavored Markdown](https://github.github.com/gfm/). An [integer overflow in ``cmark-gfm's`` table row parsing](https://github.com/github/cmark-gfm/security/advisories/GHSA-mc3g-88wq-6f4x) may lead to heap memory corruption when parsing tables who's marker rows contain more...

### Code of Conduct - [X] I have read and agree to the GitHub Docs project's [Code of Conduct](https://github.com/github/docs/blob/main/CODE_OF_CONDUCT.md) ### What article on docs.github.com is affected? https://github.com/settings/apps ### What part(s)...

content

### What version of `Wrangler` are you using? 5.5.1 ### What operating system are you using? undici (npm) ### Describe the Bug on undici in [package-lock.json](https://github.com/cloudflare/wrangler2/blob/-/package-lock.json). upgrade undici to version...

bug