es5-ext<0.10.63 vulnerable to Regular Expression Denial of Service in `function#copy` and `function#toStringTokens`
bhays-sdvi opened this issue · 1 comments
bhays-sdvi commented
Dep vulnerability: CVE-2024-27088 resolved by an upgrade of es5-ext to version 0.10.63 or later.
"es5-ext": ">=0.10.63"
medikoo commented
@bhays-sdvi thanks for reporting, I've published released that ensures only es5-ext@^0.10.64
is installed