pwnall/node-open

Security Issue reported in source clear

tnpradeep opened this issue · 2 comments

Hi Developers,

There is a high vulnerability reported in source clear.
Refer : https://www.sourceclear.com/vulnerability-database/security/command-injection/javascript/sid-6306

Is anyone working to resolve this ?

Same here. I have setup my production build to fail if 'NPM audit' returns 1. I will have to drop this package if this is issue isn't resolved soon. Please fix this or let us know when it will be fixed. Thanks

In the meantime, if you are also stuck, there is an alternative package you can use:
https://www.npmjs.com/package/opn