medikoo/cli-color

es5-ext<0.10.63 vulnerable to Regular Expression Denial of Service in `function#copy` and `function#toStringTokens`

bhays-sdvi opened this issue · 1 comments

Dep vulnerability: CVE-2024-27088 resolved by an upgrade of es5-ext to version 0.10.63 or later.

"es5-ext": ">=0.10.63"

@bhays-sdvi thanks for reporting, I've published released that ensures only es5-ext@^0.10.64 is installed