website-scraper/node-website-scraper

High NPM Vulnerability

Closed this issue · 2 comments

│ High │ Denial of Service │
├───────────────┼────────────────────────────────────────
│ Package │ css-what │
├───────────────┼────────────────────────────────────────
│ Patched in │ >=5.0.1 │
├───────────────┼────────────────────────────────────────
│ Dependency of │ website-scraper │
├───────────────┼────────────────────────────────────────
│ Path │ website-scraper > cheerio > css-select > css-what │
├───────────────┼────────────────────────────────────────

Hi @earlvhin
Thank you for reporting the issue. It's a vulnerability in one of the dependencies cheeriojs/cheerio#1924, let's wait for a fix from cheerio maintainers

aivus commented
  1. Vulnerability was fixed in css-what
  2. This security report had wrong version condition because only v4.0.0 and v5.0.0 of css-what were affected, but cheerio(via css-select) used version 2.1.