CVE in word-wrap
Nobody has claimed this yet.
Assessment
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Newbie friendliness
- 35/100
- Issue type
- Bug
- Clarity
- Mostly clear
- Activity status
- Stale
- Tech stack
- javascript
- Domain
- security
Research direction
The report identifies the dependency chain from escodegen 1.14.3 through optionator 0.8.3 to word-wrap 1.2.3. Start by checking the repository’s dependency declarations and current package setup against that chain. Done means the vulnerable path is replaced by the fixed dependency line without breaking the project’s existing checks.
Written by the indexing model from the issue text.
Description
Hi @goto-bus-stop ,
there is a CVE in word-wrap: https://github.com/jonschlinkert/word-wrap/pull/33
It is fixed and integrated in latest optionator 0.9.x, which is used in escodegen 2.x.
Is there any chance to update escodegen to 2.x?
Thanks!
escodegen@1.14.3
│ └─┬ optionator@0.8.3
│ └── word-wrap@1.2.3
Optionator team will not merge the fix to 0.8.x: https://github.com/gkz/optionator/pull/46
- Dominant language
- JavaScript
- Stars
- 177
- Forks
- 27
- PR merge metrics
- No merged PRs in 30d
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from browserify/static-eval
-
Difficulty 4/5 3-5 days Newbie friendliness 25/100
browserify/static-eval#41 · 1 comment ·
-
Difficulty 3/5 1-2 days Newbie friendliness 35/100
browserify/static-eval#39 ·
-
Difficulty 3/5 1-2 days Newbie friendliness 48/100
browserify/static-eval#38 ·
-
Difficulty 4/5 3-5 days Newbie friendliness 25/100
browserify/static-eval#34 · 20 comments · 3 reactions ·
-
Sandbox Escape Open
Difficulty 5/5 Over a week Newbie friendliness 20/100
browserify/static-eval#32 · 1 comment · 3 reactions ·
All issues in browserify/static-eval
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
HarperFast/skills#96 ·
-
[Block] Latest Posts [Type] Bug
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Automattic/studio#4908 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
sugarlabs/musicblocks#8847 ·