-
-
Notifications
You must be signed in to change notification settings - Fork 920
Closed as not planned
Labels
👎 phase/noPost cannot or will not be acted onPost cannot or will not be acted on🤷 no/invalidThis cannot be acted uponThis cannot be acted upon
Description
Initial checklist
- I read the support docs
- I read the contributing guide
- I agree to follow the code of conduct
- I searched issues and discussions and couldn’t find anything (or linked relevant results below)
Problem
A security concern was recently flagged for hast-util-to-mdast package.
| Detail | Value |
|---|---|
| Severity | moderate |
| Description | mdast-util-to-hast has unsanitized class attribute |
| Package | hast-util-to-mdast |
| Vulnerable versions | >=13.0.0, <13.2.1 |
| Patched versions | >=13.2.1 |
| Paths | .>remarkjs>hast-util-to-mdast |
| More info | GHSA-4fh9-h7wg-q85m |
Current solutions
npm audit fixProposed solutions
Update mdast-util-to-hast to ^13.2.1.
rakleed
Metadata
Metadata
Assignees
Labels
👎 phase/noPost cannot or will not be acted onPost cannot or will not be acted on🤷 no/invalidThis cannot be acted uponThis cannot be acted upon