three.interaction.js icon indicating copy to clipboard operation
three.interaction.js copied to clipboard

2 high severity vulnerabilities

Open fedekrum opened this issue 3 years ago • 1 comments

% npm install -S three.interaction

added 2 packages, and audited 3 packages in 5s

2 high severity vulnerabilities

Some issues need review, and may require choosing a different dependency.

% npm audit npm audit report

three <0.125.0 Severity: high Denial of service in three - https://github.com/advisories/GHSA-fq6p-x6j3-cmmq No fix available node_modules/three three.interaction * Depends on vulnerable versions of three node_modules/three.interaction

2 high severity vulnerabilities

Some issues need review, and may require choosing a different dependency.

fedekrum avatar Dec 21 '21 17:12 fedekrum

Can you pls share how you solve this issue?

Tosinkoa avatar Jan 23 '22 16:01 Tosinkoa