Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

The loader-utils dependency has a critical vulnerability. #13027

Closed
ManuelSLemos opened this issue Nov 7, 2022 · 2 comments · Fixed by #13021
Closed

The loader-utils dependency has a critical vulnerability. #13027

ManuelSLemos opened this issue Nov 7, 2022 · 2 comments · Fixed by #13021

Comments

@ManuelSLemos
Copy link

Hi, I have found a possible vulnerability with the loader-utils dependency.

Currently nx has as dependency loader-utils v1.2.3 and three days ago a vulnerability with these details has been reported:

loader-utils <2.0.3
Severity: critical
Prototype pollution in webpack loader-utils

More details

In my case, I found it using npm audit.

I hope it helps.

@PKief
Copy link

PKief commented Nov 7, 2022

@skrtheboss already created a PR for it: #13021

@github-actions
Copy link

This issue has been closed for more than 30 days. If this issue is still occuring, please open a new issue with more recent context.

@github-actions github-actions bot locked as resolved and limited conversation to collaborators Mar 21, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants