pkgs icon indicating copy to clipboard operation
pkgs copied to clipboard

Vulnerability in transitive execa dependency

Open gitLinda opened this issue 5 months ago • 0 comments

Hi,

We are using the @swc/cli which brings in a very old version of execa from transitive dependencies. This execa version contains a "Uncontrolled Search Path Element" vulnerability.

image

bin-check seems to be not maintained anymore, but there is a fork of available: see this issue. Unfortunately @mole-inc/bin-wrapper seems unmaintained as well.

A fix would be very appreciated.

gitLinda avatar Sep 09 '24 14:09 gitLinda