truffle-box/react-box

[Vulnerability] Remote code execution vulnerability in react-scripts > react-dev-utils

njwest opened this issue · 1 comments

There is a known remote code execution vulnerability in react-dev-utils, a dependency of react-scripts

┌───────────────┬──────────────────────────────────────────────────────────────┐
│ High          │ Remote Code Execution                                        │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package       │ react-dev-utils                                              │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ react-scripts                                                │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path          │ react-scripts > react-dev-utils                              │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info     │ https://nodesecurity.io/advisories/695                       │
└───────────────┴──────────────────────────────────────────────────────────────┘
stale commented

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.