Vulnerabilities |
3 via 5 paths |
|---|---|
Dependencies |
212 |
Source |
GitHub |
Find, fix and prevent vulnerabilities in your code.
critical severity
new
- Vulnerable module: gray-matter
- Introduced through: moleculer-cli@0.9.1
Detailed paths
-
Introduced through: moleculer-db-addons@moleculerjs/moleculer-db › moleculer-cli@0.9.1 › metalsmith@2.7.0 › gray-matter@4.0.3
Overview
gray-matter is a Parse front-matter from a string or file. Fast, reliable and easy to use. Parses YAML front matter by default, but also has support for YAML, JSON, TOML or Coffee Front-Matter, with options to set custom delimiters. Used by metalsmith, assemble, verb and
Affected versions of this package are vulnerable to Arbitrary Code Injection via the eval process in lib/engines.js when parsing front matter with the language set to js or javascript. An attacker can execute arbitrary code by supplying crafted input that is evaluated by the JavaScript engine.
Remediation
There is no fixed version for gray-matter.
References
high severity
new
- Vulnerable module: braces
- Introduced through: moleculer-cli@0.9.1
Detailed paths
-
Introduced through: moleculer-db-addons@moleculerjs/moleculer-db › moleculer-cli@0.9.1 › fast-glob@3.3.3 › micromatch@4.0.8 › braces@3.0.3
-
Introduced through: moleculer-db-addons@moleculerjs/moleculer-db › moleculer-cli@0.9.1 › metalsmith@2.7.0 › micromatch@4.0.8 › braces@3.0.3
-
Introduced through: moleculer-db-addons@moleculerjs/moleculer-db › moleculer-cli@0.9.1 › moleculer-repl@0.8.0 › fast-glob@3.3.3 › micromatch@4.0.8 › braces@3.0.3
Overview
braces is a Bash-like brace expansion, implemented in JavaScript.
Affected versions of this package are vulnerable to Uncontrolled Recursion in the recursive AST walkers, which lack depth guards. An attacker can supply deeply nested brace patterns that stay within the character limit to exhaust the call stack and crash the Node.js process with an uncaught RangeError.
Remediation
There is no fixed version for braces.
References
medium severity
new
- Vulnerable module: sprintf-js
- Introduced through: moleculer-cli@0.9.1
Detailed paths
-
Introduced through: moleculer-db-addons@moleculerjs/moleculer-db › moleculer-cli@0.9.1 › metalsmith@2.7.0 › gray-matter@4.0.3 › js-yaml@3.15.2 › argparse@1.0.10 › sprintf-js@1.0.3
Overview
Affected versions of this package are vulnerable to Improper Validation of Specified Quantity in Input via unbounded precision specifiers passed without validation to the toFixed, toExponential, and toPrecision methods. An attacker who controls a format string can inject precision values exceeding ECMAScript limits, causing uncaught RangeError exceptions that abort the calling operation.
Remediation
There is no fixed version for sprintf-js.